Skip to main content
← Back to blog

Critical Keycloak CVE-2026-18963 Enables Account Takeover via Reset Flow

A critical Keycloak password-reset vulnerability (CVE-2026-18963) may allow unauthenticated account takeover in vulnerable deployments. Teams should upgrade to fixed releases immediately and disable 'Forgot password' temporarily if patching cannot be completed at once.

#keycloak#identitysecurity#cve#accounttakeover#patchmanagement#iam
Critical Keycloak CVE-2026-18963 Enables Account Takeover via Reset Flow

Critical Keycloak Password Reset Flaw Demands Immediate Action

What happened

A critical Keycloak vulnerability, CVE-2026-18963, was disclosed and patched by upstream maintainers and Red Hat. The issue affects reset-credentials flow handling and can allow account takeover without authentication in vulnerable deployments.

Who is affected

Organizations using affected Keycloak or Red Hat build of Keycloak versions, especially environments where self-service password recovery is enabled across active realms.

Why it matters

Identity providers sit at the center of enterprise access control. A takeover path in authentication infrastructure can expose administrative access and increase the blast radius across connected applications.

Technical details

  • CVE: CVE-2026-18963
  • Severity: CVSS 9.1 (critical)
  • Weakness class: CWE-640 (weak password recovery mechanism)
  • Exploitation status: No confirmed in-the-wild exploitation reported as of publication
  • Fixed versions:
  • Upstream Keycloak 26.7.2
  • Red Hat build of Keycloak streams including 26.4.15 and 26.6.6
  • Temporary mitigation: Disable "Forgot password" on all realms if immediate patching is not possible

Recommended actions

  • Upgrade to fixed Keycloak / RHBK releases as a priority.
  • Verify reset flow settings in every realm, not only default realm configuration.
  • Temporarily disable forgot-password functionality until patching is complete where required.
  • Monitor authentication and admin logs for abnormal password reset and account lifecycle activity.
  • Reassess privileged account protections and enforce strong MFA policies.

Sources

  • https://thehackernews.com/2026/08/critical-keycloak-password-reset-flaw.html
  • https://access.redhat.com/security/cve/CVE-2026-18963
  • https://www.keycloak.org/security