Red Hat released security updates for Red Hat build of Keycloak to fix a critical account-takeover vulnerability, tracked as CVE-2026-18963, in the keycloak-services component. The flaw affects the reset-credentials flow and allows an unauthenticated remote attacker to bypass the email verification step during password recovery, reset a victim's password, and take full control of the account. Affected versions include 26.4.x before 26.4.15 and 26.6.x before 26.6.6, with scanners such as Nessus flagging vulnerable deployments based on reported version information.
Red Hat addressed the issue in advisories RHSA-2026:56523 and RHSA-2026:56524, releasing updated packages, container images, and an updated Operator for OpenShift. The advisories also bundle fixes for additional Keycloak security issues, including hidden group metadata disclosure, predictable account-linking hashes that could enable takeover through a malicious OIDC client, rotated client secret leakage via the Admin REST API, and a TOCTOU privilege-escalation bug. Red Hat advised customers to back up installations before upgrading, while Red Hat JBoss Enterprise Application Platform Expansion Pack was also listed as affected but did not yet have a vendor patch in the referenced reporting.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Red Hat published critical advisories RHSA-2026:56523 and RHSA-2026:56524 and released Red Hat build of Keycloak 26.6.6 packages and OpenShift images. The updates fixed CVE-2026-18963 along with several other vulnerabilities affecting authentication, authorization, and privilege boundaries.
The account takeover flaw CVE-2026-18963 in Keycloak's reset-credentials flow was published. The issue allows an unauthenticated attacker to bypass the email verification step and reset a target user's password.
Red Hat disclosed that Red Hat build of Keycloak 26.6.x before 26.6.6 and 26.4.x before 26.4.15 are affected by CVE-2026-18963, and recommended upgrading to 26.6.6 or 26.4.15. The notice also stated that Red Hat JBoss Enterprise Application Platform Expansion Pack was affected but did not yet have a vendor patch.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
7 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcecsirt.sk
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.