By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Threatwire
Search
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
    • Mission
    • Services
    • Contact
  • Newsletter
  • Shop
    • All Items
    • By Category
      • Drinkware
      • T-Shirts
    • Cart
Reading: Password reset bypass in Keycloak opens every account to takeover
0

No products in the cart.

  • AI
  • Android
  • Authentication
  • Breaches
  • CASB
  • Compliance
  • Cryptography
  • Cyberinsurance
  • EDR
  • IAM
  • Malware
  • Phishing
  • Quantum
  • Ransomware
  • SecOps
  • SIEM
  • SOC
  • Threat Intelligence
  • Vulnerabilities
  • Zero Trust
ThreatwireThreatwire
Font ResizerAa
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
  • Newsletter
  • Shop
Search
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
    • Mission
    • Services
    • Contact
  • Newsletter
  • Shop
    • All Items
    • By Category
    • Cart
Follow US
  • About Threatwire
  • Services
  • Contact
  • Privacy
  • Legal
©2026 CybersecurityBeat. All Rights Reserved.
News & Alerts

Password reset bypass in Keycloak opens every account to takeover

Red Hat patches a critical Keycloak flaw that lets unauthenticated attackers seize any account, including admins.

CSBadmin
Last updated: August 24, 2026 7:46 pm
CSBadmin
1 Min Read
Share
SHARE

Identity teams running Keycloak are facing a patch race: the open-source access management server has a critical hole that lets unauthenticated attackers reset any user’s password and seize the account. Red Hat and the upstream Keycloak project shipped fixes this week.

The vulnerability, tracked as CVE-2026-18963, carries a CVSS score of 9.1 and falls under the weak password recovery mechanism class (CWE-640). Red Hat’s analysis points to state-handling errors in the flow that runs when a user requests a new password. The session can be steered straight from the reset request to the password update step, skipping the emailed action token entirely.

Exploitation grants full control of any account, including administrative ones. No in-the-wild abuse has been observed and no public exploit exists as of August 24.

Upstream Keycloak 26.7.2, released August 19, contains the fix, along with Red Hat build of Keycloak 26.4.15 and 26.6.6.

For teams that cannot update right away, Red Hat’s interim fix is blunt: switch off Forgot password in every realm until the patched build is in. The setting lives under Realm settings, Login, then Forgot password in the administration console. Researcher James Paremain reported the flaw.

CSBadmin

The latest in cybersecurity news and updates.

TAGGED:Account TakeoverCVE-2026-18963Identity ManagementKeycloakPassword ResetRed Hatvulnerability
SOURCES:The Hacker News
Share This Article
Facebook Print
ByCSBadmin
Follow:
The latest in cybersecurity news and updates.
Previous Article Bogus rescue outfit double-dips on ransomware victims
Next Article Oracle’s top-severity WebLogic flaw hits CISA urgent patch list

Trending

Budget Android phones ship with malware already in the firmware
October 11, 2026
Wind and solar controls sit wide open on the web
October 10, 2026
Exposed GPU monitors hand attackers the keys to AI clusters
October 10, 2026
Unpatched backup server flaws become a path to crypto miners
October 11, 2026
Three teams bank $560,000 for cracking a Pixel 10
October 11, 2026

Related Stories

OpenAI agents flooded RubyGems with thousands of fake packages
CSBadmin

OpenAI agents flooded RubyGems with thousands of fake packages

CSBadmin

Fraudsters Build 300+ Fake Domains to Steal World Cup Ticket Credentials

CSBadmin

Stolen browser sessions let thieves drain paid Claude accounts

CSBadmin

Poisoned Git configs make AI coding agents run attacker commands

logo-twfull
  • About Threatwire
  • Services
  • Contact
  • Privacy
  • Legal

© 2026 Threatwire / Cybersecurity Beat. All rights reserved.