Critical Keycloak Password Reset Flaw Could Enable Account Takeover

IT Consultancy

IT Consultancy Get expert guidance to leverage technology for your business growth. We help you identify the right IT solutions, optimize infrastructure, and ensure your digital environment is secure,…

Digital Marketing

Digital Marketing Grow your brand and reach the right audience with data-driven marketing strategies. We help you create campaigns that convert, manage social channels effectively, and optimize your d…

Privacy Policy

Privacy Policy At CometSoul, accessible from https://cometsoul.com, one of our main priorities is the privacy of our visitors. This Privacy Policy document contains types of information that is collec…

Terms and Conditions

Welcome to CometSoul! These terms and conditions outline the rules and regulations for the use of CometSoul’s Website, located at https://cometsoul.com. By accessing this website we assume you a…

Disclaimer

If you require any more information or have any questions about our site’s disclaimer, please feel free to contact us. Disclaimers for CometSoul All the information on this website – https…

Tutorial

Wifi Managed Service

Managed Wi-Fi Service

Managed Wi-Fi Service Build a fast, stable, and secure Wi-Fi for your business at Zero depreciation cost. Enterprise-Grade Guest Wi-Fi With $0 Upfront Hardware Costs. We provide, install, and support …

System Integrator

Smart Business System Integrator

Smart Business System Integrator Simplify your daily operations with smart systems that automate bookings, schedules, and routine tasks so you can focus on growing your business. We set up and integra…

Computer Managed Service

IT Procurement & Hardware Managed Service

IT Procurement & Hardware Managed Service Keep your technology running smoothly from the hardware you use every day to the systems that power your business. We provide end-to-end IT management so …

A critical flaw has been found in the Keycloak password reset process. The issue could allow an attacker to take over an account without logging in first.

The flaw is tracked as CVE-2026-18963 and has a CVSS score of 9.1. Since Keycloak handles identity and access, the risk can be serious for affected organizations.

How Does the Flaw Work?

The issue affects the reset-credentials flow. Keycloak does not validate the reset state strongly enough.

As a result, an attacker may be able to force a password reset for another user. After that, the attacker could take control of the account.

In addition, the attack does not require a valid account first. Therefore, internet-facing Keycloak servers should be reviewed quickly.

Fixed Versions

For upstream Keycloak, the fix is available in version 26.7.2.

Meanwhile, Red Hat build of Keycloak users should update to version 26.4.15 or 26.6.6, depending on the release branch.

For this reason, administrators should check their current version and update if needed.

Temporary Mitigation

If an update cannot be installed immediately, Red Hat recommends disabling the Forgot password feature.

This setting must be disabled in every active realm.

However, this is only a temporary step. Updating to a fixed release remains the main solution.

Has It Been Exploited?

At the time of the report, there was no evidence that CVE-2026-18963 had been exploited in real-world attacks.

There was also no verified public exploit available.

Even so, an account takeover flaw should be treated seriously. This is especially true when Keycloak protects access to important applications.

Key Takeaway

CVE-2026-18963 is a serious flaw in the Keycloak password reset process. It could allow an attacker to take over an account without authentication.

Organizations should update to a fixed version as soon as possible. If patching is delayed, disable the Forgot password feature across all realms until the update is complete.

Source: https://thehackernews.com/2026/08/critical-keycloak-password-reset-flaw.html