Authorization Flaw in Keycloak Services by Red Hat
CVE-2026-18963
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 18 August 2026
Badges
What is CVE-2026-18963?
CVE-2026-18963 is a security vulnerability found in the Keycloak Services component of Red Hat's identity and access management system. Keycloak is designed to provide authentication and authorization services for applications, enabling users to access a single interface for managing their accounts securely. The vulnerability manifests within the reset-credentials flow, where an attacker can manipulate the process to reset any userβs password without possessing the necessary email verification link. This exploit allows unauthorized individuals to gain full control over target accounts by directly altering user credentials, posing a significant threat to organizations relying on Keycloak for secure user management.
Potential impact of CVE-2026-18963
-
Account Takeover: The primary risk associated with this vulnerability is the potential for unauthorized account takeover. Attackers can reset user passwords, granting them access to sensitive information and critical resources within the organization.
-
Data Breach: Successful exploitation may lead to data breaches, as attackers could access and exfiltrate confidential information stored in user accounts. This breach could have severe legal and financial implications for organizations, especially those handling sensitive personal or financial data.
-
Reputation Damage: Organizations affected by this vulnerability may face reputational harm as customers and stakeholders lose trust in their ability to secure user accounts. This loss of trust could result in decreased customer loyalty and harm to brand integrity in the broader market.
Affected Version(s)
Red Hat build of Keycloak 26.4 26.4.15-1
Red Hat build of Keycloak 26.4 26.4-23
Red Hat build of Keycloak 26.4 26.4-23
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
Critical Red Hat Keycloak Flaw Lets Unauthenticated Attackers Take Over Any User Account
Red Hat disclosed a vulnerability in Red Hat Build of Keycloak that allow unauthenticated remote attackers to take over arbitrary user accounts.
2 weeks ago

Critical Keycloak Vulnerability (CVE-2026-18963) Enables Account Takeover via Password Reset Bypass
A critical vulnerability (CVE-2026-18963, CVSS 9.1) in Keycloak allows unauthenticated attackers to hijack the password reset process by bypassing state validation, potentially taking over any account including administrative ones. Organizations should urgently upgrade to version 26.7.2 or later.
2 weeks ago
Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
Keycloak CVE-2026-18963 could let unauthenticated attackers skip the emailed action token and reset any user's password.
2 weeks ago
References
CVSS V3.1
Timeline
- π₯
Vulnerability reached the number 1 worldwide trending spot
- π
Vulnerability started trending
- π°
First article discovered by The Hacker News
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved