Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Mike Huckabee Confronts Reality of Settler Violence in West Bank

    August 25, 2026

    Image allegedly shows baby in car seat suspended outside vehicle. Is it real?

    August 25, 2026

    No, the Democratic Party is not shifting on Israel | Opinions

    August 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Mike Huckabee Confronts Reality of Settler Violence in West Bank
    • Image allegedly shows baby in car seat suspended outside vehicle. Is it real?
    • No, the Democratic Party is not shifting on Israel | Opinions
    • Trump’s Canada Tariffs Rely on Untested Law
    • G.O.P. Lawmakers Rebuke Trump on Plan to Increase Beef Imports
    • Apple’s M5 Ultra is its most powerful chip ever – with 4x faster AI performance than M3 Ultra
    • Hospital operator Nutex Health says data stolen in cyberattack
    • US dollar crackdown on Iran revives Bitcoin and gold trade
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, August 25
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 24, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalAug 24, 2026Vulnerability / Identity Security

    Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset.

    The vulnerability, assigned the CVE identifier CVE-2026-18963, is rated 9.1 on the CVSS scoring system by Red Hat, which acts as the CVE Numbering Authority (CNA) for the flaw. It has been classified as a weak password recovery mechanism for a forgotten password (CWE-640).

    Users of upstream Keycloak are advised to update to version 26.7.2, released August 19, 2026, while customers running Red Hat build of Keycloak (RHBK) should apply the updates shipped for 26.4.15 and 26.6.6.

    There is no evidence that the flaw has been exploited, and no verified public exploit has been located as of August 24, 2026.

    Red Hat said in its CVE advisory that the root cause is “improper state validation within the reset-credentials authentication flow,” the sequence Keycloak runs when a user requests password recovery. The company assessed the severity as Critical because an unauthenticated remote attacker can exploit the flaw without any user interaction.

    Cybersecurity

    The defect lies in how the flow’s state is managed, according to the Red Hat bug report. An attacker sends a specially crafted request to the reset-credentials endpoint. The authentication session then transitions directly to the password update phase. The action token that Keycloak normally sends via email is never required.

    Successful exploitation results in a complete account takeover of any user, “including administrative accounts,” by resetting their password.

    Escape researcher Enzo Mongin, writing about a separate Keycloak access-control flaw he disclosed in July, said an attacker who crosses one of the server’s boundaries does not stop at Keycloak, and that “they get into everything sitting behind it.”

    Red Hat issued four errata on August 18, 2026 (RHSA-2026:56519, RHSA-2026:56520, RHSA-2026:56523 and RHSA-2026:56524), covering the standalone server packages and the container images for two RHBK streams. The fixed versions are as follows –

    • Red Hat build of Keycloak 26.4 is unaffected from operator bundle 26.4.15-1, and from the rhbk/keycloak-rhel9 and rhbk/keycloak-rhel9-operator images 26.4-23
    • Red Hat build of Keycloak 26.6 is unaffected from operator bundle 26.6.6-1 and from the keycloak-rhel9 and operator containers 26.6-12
    • Upstream Keycloak is fixed in 26.7.2

    The GitHub advisory for the flaw lists both the affected and the patched versions as unknown, and the CVE record carries only Red Hat product references.

    The initial CVE record listed Red Hat Single Sign-On 7 as unaffected and the Red Hat JBoss Enterprise Application Platform Expansion Pack as affected. A later revision narrowed the product list, and NVD’s display truncates it, so the current status of both is not established.

    For deployments that cannot be updated immediately, Red Hat has published a temporary mitigation — turn off the “Forgot password” functionality across all realms. In the RHBK administration console, the setting sits under Realm settings, then Login, then Forgot password. Red Hat said the setting must be applied to every realm and that customers should upgrade to a fixed version as soon as possible.

    Cybersecurity

    CVE-2026-18963 was one of eight CVE identifiers listed as fixed in the Keycloak 26.7.2 release notes. The same release addressed CVE-2026-15571, a predictable account-linking hash that enables account takeover through a malicious OpenID Connect (OIDC) client.

    Two weeks earlier, on August 5, 2026, Keycloak 26.7.1 shipped fixes for twelve CVEs, including a SAML identity-provider-initiated broker login that bypassed a link-only restriction and a default dynamic client registration policy that allowed role forgery via user property mappers.

    Separately, Univention said in a post published August 20 that “Nubus is not affected by this issue” because the forgotten-password feature is not activated in its Keycloak deployments. Red Hat credited James Paremain with reporting the flaw.

    No source addresses whether the fix fully resolves the flaw.

    Whether every realm with the forgotten-password feature enabled is exploitable, or only certain reset-credentials flow configurations, is not stated by any of the published sources.

    account Attackers critical Flaw Keycloak password Reset unauthenticated
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Hospital operator Nutex Health says data stolen in cyberattack

    WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android

    WhatsApp adds stronger two-step verification, multiple passkeys

    Hackers breached over 270 Zimbra servers in ongoing attacks

    Police arrests dozens of suspects in global cybercrime crackdown

    South Korean startup platform breach exposes key management failures

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Mike Huckabee Confronts Reality of Settler Violence in West Bank

    August 25, 2026

    Image allegedly shows baby in car seat suspended outside vehicle. Is it real?

    August 25, 2026

    No, the Democratic Party is not shifting on Israel | Opinions

    August 25, 2026

    Trump’s Canada Tariffs Rely on Untested Law

    August 25, 2026
    Latest Posts

    Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates

    July 29, 2026

    Inside the rogue ChatGPT hack of Hugging Face

    July 29, 2026

    ECB wage tracker at 2.7% in Q1 2027, indicating stable negotiated wage pressures

    July 29, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Mike Huckabee Confronts Reality of Settler Violence in West Bank

    August 25, 2026

    Image allegedly shows baby in car seat suspended outside vehicle. Is it real?

    August 25, 2026

    No, the Democratic Party is not shifting on Israel | Opinions

    August 25, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.