Red Hat has disclosed a critical vulnerability in the Red Hat Build of Keycloak that allows an unauthenticated remote attacker to bypass a key safeguard in the password reset process and seize control of arbitrary user accounts.
Tracked as CVE-2026-18963, the flaw affects the keycloak-services component, the core identity and access management engine behind the enterprise Keycloak distribution. Red Hat assigned a CVSS v3.1 score of 9.1 and classified it as Critical.
Critical Red Hat Keycloak Password Reset Flaw
The vulnerable reset-credentials flow fails to validate state during password recovery. Under normal conditions, a reset request should require the affected user to follow an email verification link before new credentials can be set.
Red Hat said an attacker can force the process for any account without completing that verification step. The attacker can then directly assign a new password, obtaining full access to the targeted identity.
The vulnerability is especially significant because it has a network attack vector, is low-complexity, and requires no privileges or user interaction.
Those conditions make internet-exposed Keycloak deployments a priority for patching, particularly where the platform mediates access to workforce applications, administrative consoles, customer services, or single-sign-on environments.
Successful exploitation can compromise confidentiality and integrity, Red Hat said, while the CVSS assessment records no direct impact on availability.
Red Hat attributed the issue to improper state validation in the reset-credentials authentication flow and maps it to CWE-640, a weakness involving insufficient protection of password recovery mechanisms.
A compromised privileged account could give an intruder a route to change realm settings, create access paths, or pivot into connected applications, depending on the permissions associated with that identity. Organizations should therefore review password-reset activity, anomalous credential changes, and recent administrative logins for signs of misuse.
Red Hat issued fixes on August 18, 2026, covering Red Hat Builds of Keycloak 26.4, 26.4.15, 26.6, and 26.6.6, through the RHSA-2026:56519, RHSA-2026:56520, RHSA-2026:56523, and RHSA-2026:56524 advisories. Administrators should apply the relevant updated packages and operators as soon as possible.
Where immediate upgrades are not feasible, Red Hat recommends turning off the “Forgot password” feature in every realm by navigating to Realm settings > Login > Forgot password > Off. This workaround reduces exposure but should not replace the installation of the vendor fixes.
Red Hat’s advisory lists fixed builds for the operator bundle, RHEL 9-based Keycloak packages, OpenShift deployments, and the standalone keycloak-services component in affected release streams.
The vendor cautioned that unless a product is specifically marked as unaffected, prior package versions in a listed minor update stream should be treated as vulnerable, even when they have not undergone full analysis.
Security teams should inventory realms, confirm whether recovery is enabled, and validate that patched images are running after maintenance. Because password reset workflows cross identity, email, and application boundaries, incident responders should also invalidate suspect sessions following confirmed exploitation.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC





