vulnerability
Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
Critical
Summary
A critical vulnerability (CVE-2026-18963) in Keycloak allows unauthenticated attackers to force a password reset and take over any user account, including administrative accounts. Red Hat and Keycloak have released patches to address the issue, and a temporary mitigation involves disabling the ‘Forgot password’ functionality. The vulnerability stems from improper state validation within the password reset authentication flow.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
