Keycloak Password-Reset Flaw Enables Unauthenticated Account Takeover

1 min read
Source: The Hacker News
Keycloak Password-Reset Flaw Enables Unauthenticated Account Takeover
Photo: The Hacker News
TL;DR Summary

Red Hat and Keycloak patched a critical vulnerability (CVE-2026-18963) in the reset-credentials flow that allowed an unauthenticated attacker to bypass email verification and reset any user’s password, potentially taking over accounts including admins. Upstream Keycloak is fixed in 26.7.2; Red Hat builds require 26.4.15/26.6.6 updates. As a temporary mitigation, disable the forgot-password feature across all realms; no public exploit evidence has been found yet.

Share this article

Reading Insights

Total Reads

0

Unique Readers

7

Time Saved

3 min

vs 4 min read

Condensed

91%

68164 words

Want the full story? Read the original article

Read on The Hacker News