Critical Keycloak Flaw CVE-2026-18963 Allows Unauthenticated Account Takeover
Red Hat and the Keycloak project have released patches for a critical vulnerability, CVE-2026-18963, that could let unauthenticated attackers take over any…
Red Hat and the Keycloak project have released patches for a critical vulnerability, CVE-2026-18963, that could let unauthenticated attackers take over any…
A predictable account-linking hash in Keycloak could enable account takeover via a malicious OpenID Connect client. Fixed in version 26.7.2.
The Keycloak project released version 26.7.2 fixing CVE-2026-18963 and CVE-2026-15571, along with other security improvements. Users are urged to upgrade promptly.
Escape researcher Enzo Mongin highlighted the broader impact of Keycloak vulnerabilities, noting that attackers crossing Keycloak's boundaries can access everything behind it.
Univention stated that its Nubus product is not affected by CVE-2026-18963 because the forgotten-password feature is not activated in its Keycloak deployments.
Keycloak is an open-source identity and access management server. Versions prior to 26.7.2 are vulnerable to CVE-2026-18963, a critical account takeover flaw.
Red Hat's distribution of Keycloak is affected by CVE-2026-18963. Fixed versions include 26.4.15 and 26.6.6, with errata released on August 18, 2026.
Red Hat, as the CNA for CVE-2026-18963, released patches for its Keycloak builds and issued multiple errata. The company also provided temporary…