Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Critical Keycloak Flaw Leaves Users Vulnerable to Unauthenticated Attackers


Keycloak's critical password reset flaw leaves users vulnerable to unauthenticated attackers, who can take over any account by forcing a password reset. Red Hat has released patches to address the vulnerability, but users are advised to update to a fixed version as soon as possible.

  • Keycloak users are vulnerable to unauthenticated attackers who can take over any user account by forcing a password reset.
  • The root cause of the flaw lies in improper state validation within the reset-credentials authentication flow.
  • An attacker can bypass the normal authentication process and reset the password, allowing them to take over the account without user interaction.
  • Patches have been released to address the vulnerability, and users are advised to update to a fixed version as soon as possible.
  • There is no evidence that the flaw has been exploited, but Red Hat has warned that it could be exploited by an unauthenticated remote attacker.



  • A recent vulnerability in the open-source identity and access management server Keycloak has left users exposed to unauthenticated attackers, who can take over any user account by forcing a password reset. The vulnerability, assigned the CVE identifier CVE-2026-18963, has been rated 9.1 on the CVSS scoring system by Red Hat, the CVE Numbering Authority, and has been classified as a weak password recovery mechanism for a forgotten password (CWE-640).

    The root cause of the flaw lies in the improper state validation within the reset-credentials authentication flow, which is the sequence Keycloak runs when a user requests password recovery. An attacker can send a specially crafted request to the reset-credentials endpoint, causing the authentication session to transition directly to the password update phase. This allows the attacker to bypass the normal authentication process and reset the password, which can be used to take over the account.

    The defect in the flow's state management allows an attacker to exploit the flaw without any user interaction, making it a critical vulnerability. Successful exploitation results in a complete account takeover of any user, including administrative accounts, by resetting their password.

    Red Hat has released patches to address the vulnerability, including updates for upstream Keycloak, Red Hat build of Keycloak, and other affected products. Users of upstream Keycloak are advised to update to version 26.7.2, released August 19, 2026, while customers running Red Hat build of Keycloak (RHBK) should apply the updates shipped for 26.4.15 and 26.6.6.

    There is no evidence that the flaw has been exploited, and no verified public exploit has been located as of August 24, 2026. However, Red Hat has warned that the flaw could be exploited by an unauthenticated remote attacker, which is a critical threat.

    The initial CVE record listed Red Hat Single Sign-On 7 as unaffected and the Red Hat JBoss Enterprise Application Platform Expansion Pack as affected. A later revision narrowed the product list, and NVD's display truncates it, so the current status of both is not established.

    For deployments that cannot be updated immediately, Red Hat has published a temporary mitigation - turning off the "Forgot password" functionality across all realms. In the RHBK administration console, the setting sits under Realm settings, then Login, then Forgot password. Red Hat said the setting must be applied to every realm and that customers should upgrade to a fixed version as soon as possible.

    The vulnerability has been addressed in the Keycloak 26.7.2 release notes, which also addressed CVE-2026-15571, a predictable account-linking hash that enables account takeover through a malicious OpenID Connect (OIDC) client. Two weeks earlier, on August 5, 2026, Keycloak 26.7.1 shipped fixes for twelve CVEs, including a SAML identity-provider-initiated broker login that bypassed a link-only restriction and a default dynamic client registration policy that allowed role forgery via user property mappers.

    Separately, Univention said in a post published August 20 that "Nubus is not affected by this issue" because the forgotten-password feature is not activated in its Keycloak deployments. Red Hat credited James Paremain with reporting the flaw.

    No source addresses whether the fix fully resolves the flaw, and whether every realm with the forgotten-password feature enabled is exploitable, or only certain reset-credentials flow configurations, is not stated by any of the published sources.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Critical-Keycloak-Flaw-Leaves-Users-Vulnerable-to-Unauthenticated-Attackers-ehn.shtml

  • https://thehackernews.com/2026/08/critical-keycloak-password-reset-flaw.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-18963

  • https://www.cvedetails.com/cve/CVE-2026-18963/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-15571

  • https://www.cvedetails.com/cve/CVE-2026-15571/


  • Published: Mon Aug 24 07:40:12 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us