logo

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

ID: 3a5ded02-d07e-5ab0-b33f-166c1bbb1a70

STIX ID: report--3a5ded02-d07e-5ab0-b33f-166c1bbb1a70

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-08-24

Date Updated: 2026-08-24

Author: [email protected] (The Hacker News)

...
...

Red Hat and the Keycloak project disclosed and patched CVE-2026-18963, a critical (CVSS 9.1) improper state validation flaw in the reset-credentials flow that allows unauthenticated attackers to force password resets and fully takeover any user account (including admins). Fixed releases (upstream Keycloak 26.7.2 and Red Hat build updates) and a mitigation (disable the "Forgot password" feature per-realm) were published; no verified exploitation has been reported as of Aug 24, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.