Critical Keycloak Flaw CVE-2026-18963 Allows Unauthenticated Account Takeover
Red Hat and the Keycloak project have released patches for a critical vulnerability, CVE-2026-18963, that could let unauthenticated attackers take over any…
Red Hat and the Keycloak project have released patches for a critical vulnerability, CVE-2026-18963, that could let unauthenticated attackers take over any…
A predictable account-linking hash in Keycloak could enable account takeover via a malicious OpenID Connect client. Fixed in version 26.7.2.