Red Hat and the Keycloak project have released patches for a critical vulnerability, CVE-2026-18963, that could let unauthenticated attackers take over any user account, including administrators, by forcing a password reset. The flaw, rated 9.1 on the CVSS scale, stems from improper state validation in the reset-credentials authentication flow, allowing attackers to bypass the email token requirement.
Affected versions include upstream Keycloak (fixed in 26.7.2) and Red Hat build of Keycloak (fixed in 26.4.15 and 26.6.6). Red Hat has issued multiple errata and recommends disabling the ‘Forgot password’ feature as a temporary mitigation. No active exploitation has been reported as of August 24, 2026.
The same Keycloak 26.7.2 release also fixed CVE-2026-15571, a predictable account-linking hash issue. Earlier, version 26.7.1 addressed twelve CVEs, including SAML and OIDC related flaws. Organizations using Keycloak should upgrade immediately to prevent potential account compromise.
CVEs: CVE-2026-18963, CVE-2026-15571, CVE-2026-58231
Companies: Red Hat, Keycloak, Escape, Univention
Products: Keycloak, Red Hat build of Keycloak, Red Hat Single Sign-On 7, Red Hat JBoss Enterprise Application Platform Expansion Pack
Original source: thehackernews.com