Skip to main content
See every side of every news story
Published loading...Updated

Critical Keycloak Vulnerability (CVE-2026-18963) Enables Account Takeover via Password Reset Bypass

Summary by WebProNews
A serious security issue has surfaced in Keycloak, the popular open-source identity and access management solution used by organizations worldwide for single sign-on, OAuth flows, and application authentication. Red Hat, which maintains the project, along with the Keycloak development team, issued updates to address a high-severity vulnerability that allows unauthenticated attackers to reset passwords and potentially seize control of any account…

5 Articles

Lean Right

In the world of cybersecurity, vulnerabilities are a serious threat. Recently, a critical vulnerability was discovered in Keycloak, potentially allowing unauthorized attackers to take control of user accounts. A critical vulnerability in Keycloak's password reset process could allow unauthorized attackers to control any account. Red Hat and the Keycloak Project have released patches to address this critical vulnerability in the open-source Ident…

Read Full Article

In the Keycloak identity and access control system, attackers can misuse a password reset error to take over accounts.

·Germany
Read Full Article

The critical Keycloak password reset vulnerability could allow an unauthenticated attacker to take over any account.

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 50% of the sources are Center, 50% of the sources lean Right
50% Right

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

The Hacker News broke the news on Monday, August 24, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal