
Keycloak Password-Reset Flaw Enables Unauthenticated Account Takeover
Red Hat and Keycloak patched a critical vulnerability (CVE-2026-18963) in the reset-credentials flow that allowed an unauthenticated attacker to bypass email verification and reset any user’s password, potentially taking over accounts including admins. Upstream Keycloak is fixed in 26.7.2; Red Hat builds require 26.4.15/26.6.6 updates. As a temporary mitigation, disable the forgot-password feature across all realms; no public exploit evidence has been found yet.