Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
A serious security vulnerability in the open-source identity and access management server has been fixed by Red Hat and the Keycloak project. This vulnerability might enable an unauthenticated remote attacker to gain control of any user account by forcing a password reset.
Red Hat, the CVE Numbering Authority (CNA) for the vulnerability, has given it the CVE identifier CVE-2026-18963 and scored it 9.1 on the CVSS scoring system. It is categorized as a weak password recovery method (CWE-640).
Customers using the Red Hat build of Keycloak (RHBK) should apply the upgrades delivered for 26.4.15 and 26.6.6, while users of upstream Keycloak are recommended to update to version 26.7.2, which was released August 19, 2026.
As of August 24, 2026, there is no proof that the vulnerability ha...

