Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-25 ยท updated: 2026-08-25 ยท tags: [incident, keycloak, red-hat, password-reset, account-takeover, disclosure] ยท confidence: high ยท affected_sectors: [government, technology] ยท au_impact: false

Keycloak CVE-2026-18963 Critical Password Reset Flaw (2026-08-24)

Red Hat and the Keycloak project patched CVE-2026-18963 (CVSS 9.1), a weak password-recovery mechanism flaw (CWE-640) that lets an unauthenticated remote attacker take over arbitrary accounts by forcing password resets through improper state validation in the reset-credential flow.

Overview

Attribute Detail
Disclosed by Red Hat / Keycloak project
Date 2026-08-24
CVE CVE-2026-18963 (CVSS 9.1, CWE-640)
Impact Unauthenticated account takeover via forced password reset
Patched releases Keycloak 26.7.2; RHBK 26.4.15 and 26.6.6
Exploitation status No evidence of exploitation or public exploit as of 2026-08-24

Significance

Given Keycloak's role guarding enterprise single sign-on, defenders should treat patching as urgent before a weaponised chain appears. Open-source identity infrastructure is common across government shared services, and an unauthenticated reset-to-takeover path is the kind of bug that gets chained once public exploits land โ€” its exploitation status is worth watching in future KEV additions.

Source

Related