Red Hat has disclosed a critical vulnerability in its Build of the Keycloak identity and access management platform that could allow remote, unauthenticated attackers to take over arbitrary user accounts.
Tracked as CVE-2026-18963, the flaw stems from a bypass in the password-reset workflow and carries a CVSS v3.1 score of 9.1 out of 10.
The vulnerability affects the keycloak-services component, the core engine behind authentication and identity functions in Red Hat Build of Keycloak.
Red Hat Keycloak Password Reset Flaw
According to Red Hat, an attacker can trigger the reset-credentials process for a chosen account and set a new password without completing the required email verification step. This would give the attacker control of the victim’s account without credentials, prior access, or user interaction.
CVE-2026-18963 is rooted in improper state validation in Keycloak’s reset-credentials authentication flow. Password recovery mechanisms normally rely on a time-limited, single-use verification link delivered to an account’s registered email address.
That link is intended to prove that the person requesting a password change controls the associated mailbox. In vulnerable Red Hat Build Keycloak deployments, the password reset process can be forced forward without completing this validation.
Red Hat classified the issue as CWE-640, “Weak Password Recovery Mechanism for Forgotten Password,” a weakness category that covers recovery flows that can grant unauthorized access or enable identity assumption.
The vulnerability’s CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N, reflecting network-based exploitation with low complexity, no privileges, and no user interaction.
The primary impacts are significant loss of confidentiality and integrity: a compromised Keycloak account may expose application data and allow attackers to impersonate the victim across services protected by the affected identity provider.
Affected Keycloak releases
Red Hat published the advisory on August 17, 2026, and released fixes on August 18. Fixed standalone versions include Red Hat Build of Keycloak 26.4.15 and 26.6.6. Updated container images and operator components are also available for the 26.4 and 26.6.
| Product stream | Fixed release / advisory |
|---|---|
| Red Hat Build of Keycloak 26.4 | Updated images and operator components, RHSA-2026:56519 |
| Red Hat Build of Keycloak 26.4.15 | Fixed keycloak-services package, RHSA-2026:56520 |
| Red Hat Build of Keycloak 26.6 | Updated images and operator components, RHSA-2026:56524 |
| Red Hat Build of Keycloak 26.6.6 | Fixed keycloak-services package, RHSA-2026:56523 |
Red Hat cautions that previous packages in a listed product’s minor-update stream should be presumed vulnerable unless explicitly identified as unaffected.
Its VEX data also indicates that Red Hat Single Sign-On 7 contains no vulnerable code, while the affected component is not present in the Red Hat JBoss Enterprise Application Platform Expansion Pack.
Mitigation
Organizations should upgrade affected Keycloak environments as a priority, including standalone deployments, OpenShift-hosted instances, and operator-managed clusters.
The vendor’s 26.4.15 errata specifically identifies CVE-2026-18963 as an unauthenticated account takeover issue that is fixed in the updated images and packages.
Where an immediate upgrade is not possible, administrators can temporarily disable password recovery in every Keycloak realm:
Realm settings → Login → Forgot password → Off
Security teams should therefore treat it as a short-term control, monitor for unexpected credential changes and password-reset activity, and restore the feature only after deploying a fixed version.
Give your security team the visibility and context to investigate suspicious activity faster and contain threats before business impact grows. Strengthen Your Investigations with ANY.RUN