Vulnerability
Published 2026-08-17
Verified 2026-09-19

Red Hat Build of Keycloak account takeover via password-reset bypass (CVE-2026-18963)

Red Hat's 17 August 2026 CVE record (threat severity Critical, CVSS 3.1 9.1) describes a reset-credentials flaw in keycloak-services for Red Hat Build of Keycloak. An unauthenticated remote attacker can force password reset for any user without the email verification step and set new credentials, taking over the account. Temporary mitigation if you cannot patch yet: turn Forgot password off for every realm (Realm settings → Login). Fixed packages include Keycloak 26.4 builds at or after rhbk/keycloak-operator-bundle 26.4.15-1 / keycloak-rhel9 26.4-23 (RHSA-2026:56519 / 56520) and 26.6 builds at or after 26.6.6-1 / 26.6-12 (RHSA-2026:56523 / 56524). Red Hat marks Red Hat Single Sign-On 7 and JBoss EAP Expansion Pack as not affected. No in-the-wild exploitation stated on the Red Hat CVE page at last check.

Product
Red Hat Build of Keycloak (keycloak-services)
Versions
26.4 before fixed 26.4.15-1 / 26.4-23 packages; 26.6 before fixed 26.6.6-1 / 26.6-12 packages (see RHSA)
CVSS
(CVSS 3.1, Red Hat Critical)
Exploited in Australia?
unknown
Patch to
Apply RHSA-2026:56519/56520 (26.4) or RHSA-2026:56523/56524 (26.6); or disable Forgot password on all realms until patched

Primary: Red Hat CVE-2026-18963 · Vendor: RHSA-2026:56519 (Keycloak 26.4) · CVE: CVE-2026-18963 · RHSA-2026:56524 (Keycloak 26.6)

vulnerabilities identity