Red Hat and the Keycloak project patched CVE-2026-18963, a critical flaw in the keycloak-services component that allows an unauthenticated remote attacker to take over arbitrary accounts, including administrators. The vulnerability affects the password recovery process: improper state validation in the reset-credentials flow lets a crafted request bypass the normal email verification or action-token step and proceed directly to changing a user's password. Red Hat assigned the issue a CVSS 9.1 score and classified it as CWE-640.
Affected versions include upstream Keycloak releases earlier than 26.7.2 and Red Hat Build of Keycloak versions earlier than 26.4.15 and 26.6.6. Red Hat and CERT-PY urged organizations to apply the available security updates, while Red Hat also published a temporary mitigation for environments that cannot patch immediately by disabling the "Forgot password" feature across all realms. A Nuclei template pull request was also opened to detect the issue, underscoring rapid defender interest, although no verified public exploit or confirmed in-the-wild exploitation had been reported at publication time.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat and the Keycloak project disclosed CVE-2026-18963, a critical improper state validation flaw in the reset-credentials flow that can let unauthenticated attackers bypass the email token step and reset arbitrary users' passwords, including administrators'. Red Hat rated the issue CVSS 9.1 and recommended applying fixed versions or disabling the 'Forgot password' feature as a temporary mitigation.
A GitHub pull request for a Nuclei template covering CVE-2026-18963 was active, with DhiyaneshGeek self-assigning the work and GitHub automation marking it ready to merge, assigning ritikchaddha, and requesting review from Akokonunes.
The Keycloak project released version 26.7.2, which fixed CVE-2026-18963 among eight addressed CVEs. Users of upstream Keycloak were advised to upgrade to this version.
Red Hat issued four errata for CVE-2026-18963: RHSA-2026:56519, RHSA-2026:56520, RHSA-2026:56523, and RHSA-2026:56524, providing fixes for affected Red Hat build of Keycloak versions.
Red Hat publicly disclosed CVE-2026-18963, a critical improper state validation flaw in Keycloak's reset-credentials flow that can let unauthenticated attackers bypass email verification and take over arbitrary accounts. Red Hat rated the issue CVSS 9.1 and linked it to CWE-640.
A Rapid7 Metasploit Framework pull request added the auxiliary/admin/http/keycloak_reset_credentials_ato module to test or exploit CVE-2026-18963. The module was tested against Keycloak 26.7.1 and targets unauthenticated account takeover through the reset-credentials flow.
Technical analysis detailed how an unscoped authentication-selector flag and missing reset action-token validation in vulnerable Keycloak versions can advance a reset flow to UPDATE_PASSWORD, allowing takeover of a known-username account and issuance of an OAuth authorization code. The analysis also described 26.7.2 changes that bind the selector note to its execution and validate the action-token user ID.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
14 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcefortbridge.co.uk
Open sourcebtcirt.bt
Open sourcecsirt.bj
Open sourcecve.org
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.