PT-2026-77216 · Red Hat · Keycloak
CVE-2026-18963
·
Published
2026-08-18
·
Updated
2026-09-11
CVSS v2.0
9.4
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Keycloak versions prior to 26.7.2
Red Hat Build of Keycloak versions 26.4.x prior to 26.4.15
Red Hat Build of Keycloak versions 26.6.x prior to 26.6.6
Description
A flaw exists in the
reset-credentials flow of the keycloak-services component due to improper state validation and insufficient validation of the password-recovery state and the action-token user identifier. This allows an unauthenticated remote attacker to bypass the email verification step by sending a crafted request to the reset-credentials endpoint. Specifically, the ResetCredentialEmail.action() function fails to verify the token or the user identifier, allowing the attacker to force the password reset process and set new credentials for any account, including administrative accounts, without requiring the victim to click the verification link. Real-world exploitation of this issue has been confirmed.Recommendations
Update Keycloak to version 26.7.2 or later.
Update Red Hat Build of Keycloak to version 26.4.15 or 26.6.6 or later.
As a temporary mitigation, disable the Forgot password feature across all realms by navigating to Realm Settings → Login → Forgot password → Off.
Restrict external access to the
reset-credentials endpoint using a reverse proxy, WAF, or other access-control policies.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Keycloak