CVE Tools
Back to feed
Patch released Keycloak auth-bypass Red Hat build of Keycloak Red Hat

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

The Hacker News·By The Hacker News··3 min read
CVE Tools coverage

Red Hat and the Keycloak project have released security updates to remediate a critical vulnerability in the identity access management platform that allows unauthenticated attackers to hijack user accounts. The flaw, identified as CVE-2026-18963 and scored 9.1 by Red Hat, stems from improper state validation during the password reset process, enabling an attacker to force a credential change without verification tokens.

To secure their infrastructure, administrators should upgrade upstream Keycloak instances to version 26.7.2, or apply the corresponding fixes in Red Hat build of Keycloak versions 26.4.15 and 26.6.6. While no active exploitation has been confirmed, Red Hat recommends disabling the "Forgot password" feature in all realms as a temporary mitigation if immediate patching is not possible.