Red Hat patches critical Keycloak flaw enabling unauthenticated account takeover
This digest was compiled by AI from multiple sources — links to the originals are below.

Red Hat and the Keycloak project released patches for CVE-2026-18963, a critical flaw rated 9.1 that lets unauthenticated attackers reset any user's password. The vulnerability stems from improper state validation in the reset-credentials flow, allowing account takeover without user interaction. No exploitation has been detected as of August 24, 2026.
Key Facts
- CVE-2026-18963 is rated 9.1 on the CVSS scale by Red Hat, which acts as the CNA for the flaw.
- Upstream Keycloak users should update to version 26.7.2, released August 19, 2026.
- Red Hat issued four errata on August 18, 2026 covering RHBK 26.4.15 and 26.6.6.
- No evidence of exploitation or public exploit exists as of August 24, 2026.
Vulnerability Details
The flaw is classified as CWE-640, a weak password recovery mechanism for forgotten passwords. Red Hat's advisory states the root cause is improper state validation within the reset-credentials authentication flow. An attacker sends a crafted request to the reset-credentials endpoint, causing the session to transition directly to the password update phase without requiring the emailed action token. Successful exploitation results in complete account takeover of any user, including administrative accounts.
Patched Versions
Upstream Keycloak is fixed in version 26.7.2. Red Hat build of Keycloak 26.4 is unaffected from operator bundle 26.4.15-1 and container images 26.4-23. Red Hat build of Keycloak 26.6 is unaffected from operator bundle 26.6.6-1 and container images 26.6-12. The GitHub advisory lists affected and patched versions as unknown, and the CVE record carries only Red Hat product references.
Disclosure Status
No evidence of exploitation or a verified public exploit has been located as of August 24, 2026. Escape researcher Enzo Mongin, writing about a separate Keycloak flaw, noted that an attacker who crosses one of the server's boundaries gains access to everything behind it. The initial CVE record listed Red Hat Single Sign-On 7 as unaffected and Red Hat JBoss Enterprise Application Platform Expansion Pack as affected, but a later revision narrowed the product list.
1 source
Red Hat patches critical Keycloak flaw enabling unauthenticated account takeover



