importantSYS.SOURCE: The Hacker News• 2026-08-24T17:26:34+05:30
Critical Keycloak Password Reset Vulnerability Allows Unauthenticated Account Takeover
A critical vulnerability (CVE-2026-18963) in Keycloak allows unauthenticated attackers to take over any account via a flawed password reset mechanism. Patches are available for affected versions, with temporary mitigation advised for deployments unable to update immediately.
Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset.
The vulnerability, assigned the CVE identifier CVE-2026-18963, is rated 9.1 on the CVSS scoring system by Red Hat, which acts as
*** END OF TRANSMISSION ***