Tag

Cve 2026 18963

All articles tagged with #cve 2026 18963

Keycloak Password-Reset Flaw Enables Unauthenticated Account Takeover
security2 hours ago

Keycloak Password-Reset Flaw Enables Unauthenticated Account Takeover

Red Hat and Keycloak patched a critical vulnerability (CVE-2026-18963) in the reset-credentials flow that allowed an unauthenticated attacker to bypass email verification and reset any user’s password, potentially taking over accounts including admins. Upstream Keycloak is fixed in 26.7.2; Red Hat builds require 26.4.15/26.6.6 updates. As a temporary mitigation, disable the forgot-password feature across all realms; no public exploit evidence has been found yet.