AI description
Automated description summarized from trusted sources.
CVE-2026-18963 describes a flaw within the `reset-credentials` flow of the `keycloak-services` component, which is integral to Red Hat Build of Keycloak's identity and access management. This vulnerability stems from improper state validation during the password reset process. The flaw allows an unauthenticated attacker to bypass the required email verification link, thereby forcing a password reset for any user. This ultimately enables the attacker to gain full control over target user accounts by directly setting new credentials.
- Description
- A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.
- Source
- secalert@redhat.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 9.1
- Impact score
- 5.2
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Severity
- CRITICAL
- secalert@redhat.com
- CWE-640
- Hype score
- Not currently trending