Complete Story
 

08/25/2026

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

The Hacker News

Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset.

The vulnerability, assigned the CVE identifier CVE-2026-18963, is rated 9.1 on the CVSS scoring system by Red Hat, which acts as the CVE Numbering Authority (CNA) for the flaw. It has been classified as a weak password recovery mechanism for a forgotten password (CWE-640).

Users of upstream Keycloak are advised to update to version 26.7.2, released August 19, 2026, while customers running Red Hat build of Keycloak (RHBK) should apply the updates shipped for 26.4.15 and 26.6.6.

There is no evidence that the flaw has been exploited, and no verified public exploit has been located as of August 24, 2026.

More Info

Printer-Friendly Version