PT-2026-77216 · Red Hat · Keycloak

CVE-2026-18963

·

Published

2026-08-18

·

Updated

2026-09-11

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Keycloak versions prior to 26.7.2 Red Hat Build of Keycloak versions 26.4.x prior to 26.4.15 Red Hat Build of Keycloak versions 26.6.x prior to 26.6.6
Description A flaw exists in the reset-credentials flow of the keycloak-services component due to improper state validation and insufficient validation of the password-recovery state and the action-token user identifier. This allows an unauthenticated remote attacker to bypass the email verification step by sending a crafted request to the reset-credentials endpoint. Specifically, the ResetCredentialEmail.action() function fails to verify the token or the user identifier, allowing the attacker to force the password reset process and set new credentials for any account, including administrative accounts, without requiring the victim to click the verification link. Real-world exploitation of this issue has been confirmed.
Recommendations Update Keycloak to version 26.7.2 or later. Update Red Hat Build of Keycloak to version 26.4.15 or 26.6.6 or later. As a temporary mitigation, disable the Forgot password feature across all realms by navigating to Realm Settings → Login → Forgot password → Off. Restrict external access to the reset-credentials endpoint using a reverse proxy, WAF, or other access-control policies.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12649
BIT-KEYCLOAK-2026-18963
CVE-2026-18963
GHSA-4GV3-MC9P-5WQC

Affected Products

Keycloak