news.mlab.sh
3 results
vulnerability

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

A critical vulnerability (CVE-2026-18963) in Keycloak allows unauthenticated attackers to force a password reset and take over any user account, including administrative accounts. Red Hat and Keycloak have released patches to address the issue, and a temporary mitigation involves disabling the ‘Forgot password’ functio…

The Hacker News · 6d ago Critical