Tuesday, August 25, 2026

Critical Red Hat Keycloak Password Reset Flaw Enables Unauthenticated Account Takeover

Red Hat has disclosed a critical vulnerability in the Red Hat Build of Keycloak that allows an unauthenticated remote attacker to bypass a key safeguard in the password reset process and seize control of arbitrary user accounts.

Tracked as CVE-2026-18963, the flaw affects the keycloak-services component, the core identity and access management engine behind the enterprise Keycloak distribution. Red Hat assigned a CVSS v3.1 score of 9.1 and classified it as Critical.

Critical Red Hat Keycloak Password Reset Flaw

The vulnerable reset-credentials flow fails to validate state during password recovery. Under normal conditions, a reset request should require the affected user to follow an email verification link before new credentials can be set.

Red Hat said an attacker can force the process for any account without completing that verification step. The attacker can then directly assign a new password, obtaining full access to the targeted identity.

The vulnerability is especially significant because it has a network attack vector, is low-complexity, and requires no privileges or user interaction.

Those conditions make internet-exposed Keycloak deployments a priority for patching, particularly where the platform mediates access to workforce applications, administrative consoles, customer services, or single-sign-on environments.

Successful exploitation can compromise confidentiality and integrity, Red Hat said, while the CVSS assessment records no direct impact on availability.

Red Hat attributed the issue to improper state validation in the reset-credentials authentication flow and maps it to CWE-640, a weakness involving insufficient protection of password recovery mechanisms.

A compromised privileged account could give an intruder a route to change realm settings, create access paths, or pivot into connected applications, depending on the permissions associated with that identity. Organizations should therefore review password-reset activity, anomalous credential changes, and recent administrative logins for signs of misuse.

Red Hat issued fixes on August 18, 2026, covering Red Hat Builds of Keycloak 26.4, 26.4.15, 26.6, and 26.6.6, through the RHSA-2026:56519, RHSA-2026:56520, RHSA-2026:56523, and RHSA-2026:56524 advisories. Administrators should apply the relevant updated packages and operators as soon as possible.

Where immediate upgrades are not feasible, Red Hat recommends turning off the “Forgot password” feature in every realm by navigating to Realm settings > Login > Forgot password > Off. This workaround reduces exposure but should not replace the installation of the vendor fixes.

Red Hat’s advisory lists fixed builds for the operator bundle, RHEL 9-based Keycloak packages, OpenShift deployments, and the standalone keycloak-services component in affected release streams.

The vendor cautioned that unless a product is specifically marked as unaffected, prior package versions in a listed minor update stream should be treated as vulnerable, even when they have not undergone full analysis.

Security teams should inventory realms, confirm whether recovery is enabled, and validate that patched images are running after maintenance. Because password reset workflows cross identity, email, and application boundaries, incident responders should also invalidate suspect sessions following confirmed exploitation.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

EvilTokens Abuses Microsoft Device Codes to Hijack Accounts Without Stealing Passwords

EvilTokens is pushing phishing-as-a-service beyond credential theft by abusing...

TP-Link Archer Command Injection Flaws Enable Root-Level Code Execution

TP-Link has released firmware updates for three Archer router...

Fake GTA 6 Demo Sites Spread Vidar Stealer to Hijack Authenticated Browser Sessions

Cybercriminals are capitalizing on renewed interest in Grand Theft...

WeedHack Malware Spreads Through SEO-Poisoned Minecraft Sites Despite C2 Disruption

A renewed distribution wave for the WeedHack malware-as-a-service operation,...

Hackers Exploit Critical Oracle HTTP Server Flaw to Access and Modify Sensitive Data

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Microsoft Teams New Security Policy Lets Admins Automatically Block Meeting Bots

Microsoft is introducing a new Microsoft Teams meeting policy...

5 Palo Alto GlobalProtect Flaws Let Attackers Gain SYSTEM/Root Access and Steal AD Passwords

Security researcher Martijn van Ramesdonk has disclosed five vulnerabilities...

Related Articles

Recent News