CVE-2026-18963

Published Aug 18, 2026

Last updated a month ago

CVSS critical 9.1
OT
Red Hat Build of Keycloak
Keycloak

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-18963 describes a flaw within the `reset-credentials` flow of the `keycloak-services` component, which is integral to Red Hat Build of Keycloak's identity and access management. This vulnerability stems from improper state validation during the password reset process. The flaw allows an unauthenticated attacker to bypass the required email verification link, thereby forcing a password reset for any user. This ultimately enables the attacker to gain full control over target user accounts by directly setting new credentials.

Description
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.
Source
secalert@redhat.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.1
Impact score
5.2
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity
CRITICAL

Weaknesses

secalert@redhat.com
CWE-640

Social media

Hype score
Not currently trending
  1. HCL Software patched critical HCL BigFix vulnerabilities, including CVE-2026-67100 and CVE-2026-18963. Patch now to prevent total account takeovers. #HCLBigFix #Cybersecurity #CVE202667100 #Vulnerability #InfoSec https://t.co/cpTNlrOb3Z

    @Daily_CyberSec

    18 Sept 2026

    402 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 CVE-2026-18963 is a critical Keycloak account-takeover flaw in the password reset flow. Learn how to test safely, hunt for traces, and apply mitigations. #Keycloak #CVE https://t.co/fRJc523csz https://t.co/XeX8JprhrY

    @ShellCodeXHQ

    11 Sept 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Two critical Siemens vulnerabilities (CVE-2026-18963, CVE-2026-50093) allow account takeover and root access. See affected versions and fixes. #Siemens #CyberSecurity #ICS #OTSecurity #CVE #IndustrialEdge #Vulnerability #InfoSec https://t.co/9lWOOxHDec https://t.co/Qa7PvpQHrs

    @Daily_CyberSec

    9 Sept 2026

    368 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Red Hat Keycloak 脆弱性 CVE-2026-18963 が FIX:パスワード・リセットによるアカウント乗っ取りの恐れ https://t.co/ByyrtyjAMn Red Hat Keycloak

    @iototsecnews

    1 Sept 2026

    113 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. アプリのログインやシングルサインオンを担う認証基盤「Keycloak」に、任意の利用者アカウントを奪える脆弱性「CVE-2026-18963」。パスワード再設定の処理で、検証用メールのリンクを踏ませる工程を飛ばせてし

    @MalwareBibleJP

    31 Aug 2026

    1414 Impressions

    1 Retweet

    8 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  6. Critical Keycloak Vulnerability (CVE-2026-18963) Enables Account Takeover via Password Reset Bypass CVSS 9.1 | CVE-2026-18963 PoC: https://t.co/TujkZdOXR9

    @_aircorridor

    25 Aug 2026

    494 Impressions

    2 Retweets

    6 Likes

    1 Bookmark

    2 Replies

    0 Quotes

  7. 🚨 Critical Keycloak flaw can enable full account takeover. Red Hat and Keycloak have patched CVE-2026-18963, a critical vulnerability rated 9.1 CVSS. The flaw allows an unauthenticated remote attacker to bypass the normal password-reset process and reset a victim’s passwor

    @ZeroDayFacts

    25 Aug 2026

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. A critical Keycloak flaw (CVE-2026-18963) allows remote account takeover via password reset bypass. Patch immediately. #keycloak #vulnerability #authentication #identity https://t.co/kXjjhc965k

    @mergenewsapp

    25 Aug 2026

    20 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Keycloak CVE-2026-18963 PoC Unauthenticated password reset flow bypass https://t.co/VC3zv8kazv #CVE #PoC #CyberSecurity #InfoSec #RCE #Vulnerability #Keycloak

    @T0ww0T

    24 Aug 2026

    134 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Keycloak is vulnerable to a critical unauthenticated account takeover (CVE-2026-18963) I reproduced the bug locally; interesting one (power of LLM, I think) https://t.co/hBuQe28aEm https://t.co/QfUjdxpx28

    @h4x0r_dz

    23 Aug 2026

    93473 Impressions

    121 Retweets

    843 Likes

    588 Bookmarks

    12 Replies

    5 Quotes

  11. An attacker needs only reach to your Keycloak login page. CVE-2026-18963 bypasses the reset-credentials flow into full account takeover. Fixed in 26.7.2, one of eight. @keycloak #appsec #selfhosted

    @elest_io

    23 Aug 2026

    91 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    1 Quote

  12. A Keycloak account takeover flaw, CVE-2026-18963, lets attackers reset any user's password with no email verification. Update to 26.7.2 now. #Keycloak #AccountTakeover #CVE #IAM #InfoSec #RedHat https://t.co/iYx7mFwXz8

    @Daily_CyberSec

    21 Aug 2026

    2446 Impressions

    18 Retweets

    52 Likes

    21 Bookmarks

    0 Replies

    1 Quote