news.mlab.sh
Back to the feed
vulnerability

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Critical
Image: The Hacker News
Summary

A critical vulnerability (CVE-2026-18963) in Keycloak allows unauthenticated attackers to force a password reset and take over any user account, including administrative accounts. Red Hat and Keycloak have released patches to address the issue, and a temporary mitigation involves disabling the ‘Forgot password’ functionality. The vulnerability stems from improper state validation within the password reset authentication flow.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.