Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Chronological Source Flow
Back

AI Fusion Summary

Red Hat and the Keycloak project patched CVE-2026-18963, a critical improper state validation bug in the reset-credentials flow. This flaw allows unauthenticated remote attackers to bypass emailed action tokens and jump directly to password updates, enabling full takeover of any account, including administrative ones. Red Hat assigned it a CVSS score of 9.1. Users should upgrade to Keycloak 26.7.2, 26.4.15, or 26.6.6, or disable the Forgot password setting under Realm settings to mitigate the risk.
Community Comments
Loading updates...
0