Critical Keycloak Password Reset Flaw Demands Immediate Action
What happened
A critical Keycloak vulnerability, CVE-2026-18963, was disclosed and patched by upstream maintainers and Red Hat. The issue affects reset-credentials flow handling and can allow account takeover without authentication in vulnerable deployments.
Who is affected
Organizations using affected Keycloak or Red Hat build of Keycloak versions, especially environments where self-service password recovery is enabled across active realms.
Why it matters
Identity providers sit at the center of enterprise access control. A takeover path in authentication infrastructure can expose administrative access and increase the blast radius across connected applications.
Technical details
- CVE: CVE-2026-18963
- Severity: CVSS 9.1 (critical)
- Weakness class: CWE-640 (weak password recovery mechanism)
- Exploitation status: No confirmed in-the-wild exploitation reported as of publication
- Fixed versions:
- Upstream Keycloak 26.7.2
- Red Hat build of Keycloak streams including 26.4.15 and 26.6.6
- Temporary mitigation: Disable "Forgot password" on all realms if immediate patching is not possible
Recommended actions
- Upgrade to fixed Keycloak / RHBK releases as a priority.
- Verify reset flow settings in every realm, not only default realm configuration.
- Temporarily disable forgot-password functionality until patching is complete where required.
- Monitor authentication and admin logs for abnormal password reset and account lifecycle activity.
- Reassess privileged account protections and enforce strong MFA policies.
Sources
- https://thehackernews.com/2026/08/critical-keycloak-password-reset-flaw.html
- https://access.redhat.com/security/cve/CVE-2026-18963
- https://www.keycloak.org/security
