CVE-2026-18963

Published Aug 18, 2026

Last updated 2 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-18963 describes a flaw within the `reset-credentials` flow of the `keycloak-services` component, which is integral to Red Hat Build of Keycloak's identity and access management. This vulnerability stems from improper state validation during the password reset process. The flaw allows an unauthenticated attacker to bypass the required email verification link, thereby forcing a password reset for any user. This ultimately enables the attacker to gain full control over target user accounts by directly setting new credentials.

Description
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.
Source
secalert@redhat.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.1
Impact score
5.2
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity
CRITICAL

Weaknesses

secalert@redhat.com
CWE-640

Social media

Hype score
Not currently trending