Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

August 24, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Organizations using Keycloak or Red Hat build of Keycloak (RHBK)
Incident: Discovery of a critical password reset vulnerability (CVE-2026-18963) in the Keycloak identity server.
Impact: Complete unauthorized account takeover of any user, including administrative accounts.
Attacker: Unidentified threat actors
Analysis: The flaw, identified as CVE-2026-18963, results from improper state validation within the reset-credentials authentication flow. Attackers can bypass the required email verification token and transition directly to the password update phase. This allows for full account takeover, including administrative privileges, without any user interaction.
Recommendations: Update upstream Keycloak to version 26.7.2 or apply RHBK updates for 26.4.15 and 26.6.6.; Review authentication logs for unauthorized password reset requests.; Temporarily disable the forgotten-password feature if immediate patching is not possible.
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *