Keycloak password reset flaw allows unauthenticated account takeover
Source headline: Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
Intelligence Summary
Red Hat and the Keycloak project released patches for a critical password reset security flaw in the identity and access management server. The issue is tracked as CVE-2026-18963. Red Hat rates it 9.1 on the CVSS scoring system. The vulnerability could let an unauthenticated remote attacker take over any user account by forcing a password reset. Users should apply the Keycloak patches released by Red Hat and the Keycloak project as soon as possible.
Recommended Action
Check whether your Keycloak deployment is affected by CVE-2026-18963 (CVSS 9.1) and apply the vendor fix. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.