Keycloak password-reset account takeover flaw (CVE-2026-18963)
Vulnerability
Summary
Hide ▲
Show ▼
Patches are available for CVE-2026-18963 in Keycloak, closing a critical password-reset flaw that could let an unauthenticated remote attacker seize any user account, including administrative accounts. The weakness is an improper state validation bug in the reset-credentials flow, where a crafted request can jump straight to password update without the normal email action token. Fixed builds are Keycloak 26.7.2 and Red Hat build of Keycloak 26.4.15 / 26.6.6, with a temporary workaround to disable Forgot password.
Related Happenings
CISA SmarterMail remediation guidance for CVE-2026-24423
Advisory/Mitigation
H score86
First: 06.02.2026 19:16
Last: 06.02.2026 19:16
Sources 1
About this happening:
SmarterMail is at the center of a CVE-2026-24423 remediation and exploitation wave: the flaw enables unauthenticated remote code execution in versions prior to Build...
CISA SmarterMail remediation guidance for CVE-2026-24423
Advisory/MitigationAbout this happening: SmarterMail is at the center of a CVE-2026-24423 remediation and exploitation wave: the flaw enables unauthenticated remote code execution in versions prior to Build...
SmarterMail CVE-2026-23760 mass exploitation wave
Exploitation Wave
H score89
First: 27.01.2026 16:09
Last: 27.01.2026 16:09
Sources 1
About this happening:
CVE-2026-23760 is being exploited against SmarterMail to bypass authentication on internet-facing mail servers, creating takeover risk across thousands of exposed in...
SmarterMail CVE-2026-23760 mass exploitation wave
Exploitation WaveAbout this happening: CVE-2026-23760 is being exploited against SmarterMail to bypass authentication on internet-facing mail servers, creating takeover risk across thousands of exposed in...
Timeline
-
24.08.2026 14:56 1 articles · 9h ago
Red Hat patches Keycloak CVE-2026-18963
Initial DisclosureRed Hat and the Keycloak project released patches for CVE-2026-18963, a critical reset-credentials flaw in Keycloak that could let an unauthenticated remote attacker force a password reset and take over any user account, including administrative accounts.
Show sources
- Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account — thehackernews.com — 24.08.2026 14:56
-
24.08.2026 14:56 1 articles · 9h ago
Keycloak 26.7.2 ships the fix for the password-reset takeover flaw
Mitigation Patch UpdateUpstream Keycloak 26.7.2 shipped with the fix for CVE-2026-18963, alongside Red Hat build of Keycloak updates for the 26.4 and 26.6 streams.
Show sources
- Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account — thehackernews.com — 24.08.2026 14:56
-
24.08.2026 14:56 2 articles · 9h ago
Red Hat says CVE-2026-18963 has no known exploitation and advises disabling Forgot password
Mitigation Patch UpdateRed Hat said there was no evidence that CVE-2026-18963 had been exploited as of August 24, 2026, and advised affected Keycloak deployments to disable the Forgot password setting across all realms until they can upgrade to a fixed version.
Show sources
- Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account — thehackernews.com — 24.08.2026 14:56
- Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account — thehackernews.com — 24.08.2026 14:56