Critical Keycloak Vulnerability (CVE-2026-18963) Enables Account Takeover via Password Reset Bypass
5 Articles
5 Articles
Critical Keycloak Vulnerability (CVE-2026-18963) Enables Account Takeover via Password Reset Bypass
A serious security issue has surfaced in Keycloak, the popular open-source identity and access management solution used by organizations worldwide for single sign-on, OAuth flows, and application authentication. Red Hat, which maintains the project, along with the Keycloak development team, issued updates to address a high-severity vulnerability that allows unauthenticated attackers to reset passwords and potentially seize control of any account…
In the world of cybersecurity, vulnerabilities are a serious threat. Recently, a critical vulnerability was discovered in Keycloak, potentially allowing unauthorized attackers to take control of user accounts. A critical vulnerability in Keycloak's password reset process could allow unauthorized attackers to control any account. Red Hat and the Keycloak Project have released patches to address this critical vulnerability in the open-source Ident…
In the Keycloak identity and access control system, attackers can misuse a password reset error to take over accounts.
The critical Keycloak password reset vulnerability could allow an unauthenticated attacker to take over any account.
Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset. The vulnerability, assigned the CVE identifier CVE-2026-18963, is rated 9.1 on the CVSS scoring system by Red Hat, which acts as
Coverage Details
Bias Distribution
- 50% of the sources are Center, 50% of the sources lean Right
Factuality
To view factuality data please Upgrade to Premium







