Red HatCVE-2026-18963
reset-credentials flow of the keycloak-services: weak password recovery
Critical9.1CVE-2026-18963 · Published Aug 18, 2026 · updated Sep 8, 2026
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat JBoss Enterprise Application Platform Expansion Pack Product | all versions | No fix yet |
| Red Hat build of Keycloak 26.4.15 Product | all versions | No fix yet |
| all versions | No fix yet | |
| Red Hat build of Keycloak 26.6.6 Product | all versions | No fix yet |
| all versions | No fix yet | |
| all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-640
- www.cve.org/CVERecord?id=CVE-2026-18963
- nvd.nist.gov/vuln/detail/CVE-2026-18963
- access.redhat.com/errata/RHSA-2026:56519
- access.redhat.com/errata/RHSA-2026:56520
- access.redhat.com/errata/RHSA-2026:56523
- access.redhat.com/errata/RHSA-2026:56524
- access.redhat.com/security/cve/CVE-2026-18963
- bugzilla.redhat.com/show_bug.cgi?id=2511595
- cert-portal.siemens.com/productcert/html/ssa-503852.html
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 18 | A flaw was found in the legacy client-initiated account-linking endpoint of... | High7.3 | No fix yet |
| Aug 18 | Red Hat Advanced Cluster Management for Kubernetes 2: secrets in logs | Medium6.5 | No fix yet |
| Aug 18 | Red Hat Multicluster Engine for Kubernetes: information disclosure | High8.7 | No fix yet |
| Aug 18 | Red Hat Advanced Cluster Management for Kubernetes 2: information disclosure | Medium5.4 | No fix yet |
| Aug 18 | Red Hat Advanced Cluster Management: improper privilege management | Medium5.8 | No fix yet |
| Aug 18 | Red Hat Advanced Cluster Management for Kubernetes 2: code execution | Medium4.4 | No fix yet |