Multiples vulnérabilités dans Keycloak (25 août 2026)
Multiple vulnerabilities have been discovered in Keycloak, allowing an attacker to bypass security policies and potentially take control of an account if they know its identifier. The CERT-FR has a proof of concept for CVE-2026-18963. Red Hat recommends disabling the 'Forgot password' feature as a temporary mitigation until updates are applied.
Multiple vulnerabilities have been identified in Keycloak. These vulnerabilities allow an attacker to circumvent security policies and potentially gain control of an account if they know the account identifier. The CERT-FR is aware of a public proof of concept for CVE-2026-18963, which demonstrates this bypass. Red Hat recommends disabling the ‘Forgot password’ feature for all authentication domains as a temporary mitigation until updates are applied. The vulnerabilities include CVE-2026-14613, CVE-2026-15571, CVE-2026-15945, CVE-2026-17048, CVE-2026-18963, CVE-2026-45292 and CVE-2026-59888. Users of Keycloak versions prior to 26.7.2 are affected. Refer to the Keycloak security bulletin from August 19, 2026, and the Red Hat article on CVE-2026-18963 for more details and available patches.