By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Threatwire
Search
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
    • Mission
    • Services
    • Contact
  • Newsletter
  • Shop
    • All Items
    • By Category
      • Drinkware
      • T-Shirts
    • Cart
Reading: Password reset bypass in Keycloak opens every account to takeover
0

No products in the cart.

  • AI
  • Android
  • Authentication
  • Breaches
  • CASB
  • Compliance
  • Cryptography
  • Cyberinsurance
  • EDR
  • IAM
  • Malware
  • Phishing
  • Quantum
  • Ransomware
  • SecOps
  • SIEM
  • SOC
  • Threat Intelligence
  • Vulnerabilities
  • Zero Trust
ThreatwireThreatwire
Font ResizerAa
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
  • Newsletter
  • Shop
Search
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
    • Mission
    • Services
    • Contact
  • Newsletter
  • Shop
    • All Items
    • By Category
    • Cart
Follow US
  • About Threatwire
  • Services
  • Contact
  • Privacy
  • Legal
©2026 CybersecurityBeat. All Rights Reserved.
News & Alerts

Password reset bypass in Keycloak opens every account to takeover

Red Hat patches a critical Keycloak flaw that lets unauthenticated attackers seize any account, including admins.

CSBadmin
Last updated: August 24, 2026 7:46 pm
CSBadmin
1 Min Read
Share
SHARE

Identity teams running Keycloak are facing a patch race: the open-source access management server has a critical hole that lets unauthenticated attackers reset any user’s password and seize the account. Red Hat and the upstream Keycloak project shipped fixes this week.

The vulnerability, tracked as CVE-2026-18963, carries a CVSS score of 9.1 and falls under the weak password recovery mechanism class (CWE-640). Red Hat’s analysis points to state-handling errors in the flow that runs when a user requests a new password. The session can be steered straight from the reset request to the password update step, skipping the emailed action token entirely.

Exploitation grants full control of any account, including administrative ones. No in-the-wild abuse has been observed and no public exploit exists as of August 24.

Upstream Keycloak 26.7.2, released August 19, contains the fix, along with Red Hat build of Keycloak 26.4.15 and 26.6.6.

For teams that cannot update right away, Red Hat’s interim fix is blunt: switch off Forgot password in every realm until the patched build is in. The setting lives under Realm settings, Login, then Forgot password in the administration console. Researcher James Paremain reported the flaw.

CSBadmin

The latest in cybersecurity news and updates.

TAGGED:Account TakeoverCVE-2026-18963Identity ManagementKeycloakPassword ResetRed Hatvulnerability
SOURCES:The Hacker News
Share This Article
Facebook Print
ByCSBadmin
Follow:
The latest in cybersecurity news and updates.
Previous Article Bogus rescue outfit double-dips on ransomware victims

Trending

Bogus rescue outfit double-dips on ransomware victims
August 24, 2026
Linux rig joins Apple Find My to pull live location feeds
August 24, 2026
764 offshoot leader gets record 77-year term for abuse spree
August 24, 2026
Slovak watchdog pulls speed cameras over hacking and data risks
August 24, 2026
Graduation invites hide Go backdoor aimed at Myanmar officials
August 24, 2026

Related Stories

CSBadmin

LastPass Confirms Customer Data Exposure in Klue OAuth Supply Chain Attack

CSBadmin

Mass Email Floods Precede Fake Teams IT Support in New Wave of Breaches

CSBadmin

Fake Software Installers Deliver Stealthy SharkLoader Malware Worldwide

CSBadmin

Chinese hacking subgroup linked to DigiCert breach and code-signing certificate theft

logo-twfull
  • About Threatwire
  • Services
  • Contact
  • Privacy
  • Legal

© 2026 Threatwire / Cybersecurity Beat. All rights reserved.