Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
Red Hat and the Keycloak project have released security updates to remediate a critical vulnerability in the identity access management platform that allows unauthenticated attackers to hijack user accounts. The flaw, identified as CVE-2026-18963 and scored 9.1 by Red Hat, stems from improper state validation during the password reset process, enabling an attacker to force a credential change without verification tokens.
To secure their infrastructure, administrators should upgrade upstream Keycloak instances to version 26.7.2, or apply the corresponding fixes in Red Hat build of Keycloak versions 26.4.15 and 26.6.6. While no active exploitation has been confirmed, Red Hat recommends disabling the "Forgot password" feature in all realms as a temporary mitigation if immediate patching is not possible.