type: incident ยท created: 2026-08-25 ยท updated: 2026-08-25 ยท tags: [incident, keycloak, red-hat, password-reset, account-takeover, disclosure] ยท confidence: high ยท affected_sectors: [government, technology] ยท au_impact: false
Keycloak CVE-2026-18963 Critical Password Reset Flaw (2026-08-24)
Red Hat and the Keycloak project patched CVE-2026-18963 (CVSS 9.1), a weak password-recovery mechanism flaw (CWE-640) that lets an unauthenticated remote attacker take over arbitrary accounts by forcing password resets through improper state validation in the reset-credential flow.
Overview
| Attribute | Detail |
|---|---|
| Disclosed by | Red Hat / Keycloak project |
| Date | 2026-08-24 |
| CVE | CVE-2026-18963 (CVSS 9.1, CWE-640) |
| Impact | Unauthenticated account takeover via forced password reset |
| Patched releases | Keycloak 26.7.2; RHBK 26.4.15 and 26.6.6 |
| Exploitation status | No evidence of exploitation or public exploit as of 2026-08-24 |
Significance
Given Keycloak's role guarding enterprise single sign-on, defenders should treat patching as urgent before a weaponised chain appears. Open-source identity infrastructure is common across government shared services, and an unauthenticated reset-to-takeover path is the kind of bug that gets chained once public exploits land โ its exploitation status is worth watching in future KEV additions.
Source
- The Hacker News โ Critical Keycloak Password Reset Flaw โ 2026-08-24
Related
- Cve 2026 18963 โ the underlying vulnerability