CVE-2026-18963
Published Aug 18, 2026
Last updated a month ago
AI description
CVE-2026-18963 describes a flaw within the `reset-credentials` flow of the `keycloak-services` component, which is integral to Red Hat Build of Keycloak's identity and access management. This vulnerability stems from improper state validation during the password reset process. The flaw allows an unauthenticated attacker to bypass the required email verification link, thereby forcing a password reset for any user. This ultimately enables the attacker to gain full control over target user accounts by directly setting new credentials.
- Description
- A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.
- Source
- secalert@redhat.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 9.1
- Impact score
- 5.2
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Severity
- CRITICAL
- secalert@redhat.com
- CWE-640
- Hype score
- Not currently trending
HCL Software patched critical HCL BigFix vulnerabilities, including CVE-2026-67100 and CVE-2026-18963. Patch now to prevent total account takeovers. #HCLBigFix #Cybersecurity #CVE202667100 #Vulnerability #InfoSec https://t.co/cpTNlrOb3Z
@Daily_CyberSec
18 Sept 2026
402 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-18963 is a critical Keycloak account-takeover flaw in the password reset flow. Learn how to test safely, hunt for traces, and apply mitigations. #Keycloak #CVE https://t.co/fRJc523csz https://t.co/XeX8JprhrY
@ShellCodeXHQ
11 Sept 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Two critical Siemens vulnerabilities (CVE-2026-18963, CVE-2026-50093) allow account takeover and root access. See affected versions and fixes. #Siemens #CyberSecurity #ICS #OTSecurity #CVE #IndustrialEdge #Vulnerability #InfoSec https://t.co/9lWOOxHDec https://t.co/Qa7PvpQHrs
@Daily_CyberSec
9 Sept 2026
368 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Red Hat Keycloak 脆弱性 CVE-2026-18963 が FIX:パスワード・リセットによるアカウント乗っ取りの恐れ https://t.co/ByyrtyjAMn Red Hat Keycloak
@iototsecnews
1 Sept 2026
113 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
アプリのログインやシングルサインオンを担う認証基盤「Keycloak」に、任意の利用者アカウントを奪える脆弱性「CVE-2026-18963」。パスワード再設定の処理で、検証用メールのリンクを踏ませる工程を飛ばせてし
@MalwareBibleJP
31 Aug 2026
1414 Impressions
1 Retweet
8 Likes
2 Bookmarks
0 Replies
0 Quotes
Critical Keycloak Vulnerability (CVE-2026-18963) Enables Account Takeover via Password Reset Bypass CVSS 9.1 | CVE-2026-18963 PoC: https://t.co/TujkZdOXR9
@_aircorridor
25 Aug 2026
494 Impressions
2 Retweets
6 Likes
1 Bookmark
2 Replies
0 Quotes
🚨 Critical Keycloak flaw can enable full account takeover. Red Hat and Keycloak have patched CVE-2026-18963, a critical vulnerability rated 9.1 CVSS. The flaw allows an unauthenticated remote attacker to bypass the normal password-reset process and reset a victim’s passwor
@ZeroDayFacts
25 Aug 2026
18 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
A critical Keycloak flaw (CVE-2026-18963) allows remote account takeover via password reset bypass. Patch immediately. #keycloak #vulnerability #authentication #identity https://t.co/kXjjhc965k
@mergenewsapp
25 Aug 2026
20 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Keycloak CVE-2026-18963 PoC Unauthenticated password reset flow bypass https://t.co/VC3zv8kazv #CVE #PoC #CyberSecurity #InfoSec #RCE #Vulnerability #Keycloak
@T0ww0T
24 Aug 2026
134 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Keycloak is vulnerable to a critical unauthenticated account takeover (CVE-2026-18963) I reproduced the bug locally; interesting one (power of LLM, I think) https://t.co/hBuQe28aEm https://t.co/QfUjdxpx28
@h4x0r_dz
23 Aug 2026
93473 Impressions
121 Retweets
843 Likes
588 Bookmarks
12 Replies
5 Quotes
An attacker needs only reach to your Keycloak login page. CVE-2026-18963 bypasses the reset-credentials flow into full account takeover. Fixed in 26.7.2, one of eight. @keycloak #appsec #selfhosted
@elest_io
23 Aug 2026
91 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
1 Quote
A Keycloak account takeover flaw, CVE-2026-18963, lets attackers reset any user's password with no email verification. Update to 26.7.2 now. #Keycloak #AccountTakeover #CVE #IAM #InfoSec #RedHat https://t.co/iYx7mFwXz8
@Daily_CyberSec
21 Aug 2026
2446 Impressions
18 Retweets
52 Likes
21 Bookmarks
0 Replies
1 Quote