CVE-2026-18963: Weak Password Recovery Mechanism for Forgotten Password in Red Hat Red Hat build of Keycloak 26.4
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.
AI Analysis
Technical Summary
This vulnerability exists in the reset-credentials flow of the keycloak-services component, which is the core identity and access management engine in Red Hat build of Keycloak. The flaw allows an unauthenticated remote attacker to force the password reset process for any user without clicking the required email verification link. The root cause is improper state validation in the reset-credentials authentication flow. Exploitation results in the attacker gaining full access to target user accounts by directly setting new credentials. The vulnerability has a CVSS v3.1 base score of 9.1 (critical) with network attack vector, low complexity, no privileges or user interaction required, and high confidentiality and integrity impacts. Red Hat has published a security advisory and released a fixed version 26.6.6 that addresses this issue.
Potential Impact
An unauthenticated attacker can bypass the email verification step in the password reset process and reset passwords for any user account. This leads to complete account takeover, compromising confidentiality and integrity of user accounts. There is no impact on availability. The vulnerability allows full control over user identities without requiring any authentication or user interaction.
Mitigation Recommendations
Red Hat recommends upgrading to the fixed version 26.6.6 of Red Hat build of Keycloak as soon as possible. As a temporary mitigation, if immediate upgrade is not feasible, administrators can disable the "Forgot password" functionality across all realms via the administration console (Realm settings → Login → Forgot password → Off). This prevents exploitation by blocking the vulnerable password reset flow until a patch can be applied.
CVE-2026-18963: Weak Password Recovery Mechanism for Forgotten Password in Red Hat Red Hat build of Keycloak 26.4
Description
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.
CVSS v3.1
Score 9.1critical
Affected software
Red Hat
Red Hat build of Keycloak 26.4
Red Hat
Red Hat build of Keycloak 26.4
Red Hat
Red Hat build of Keycloak 26.4.15
Red Hat
Red Hat build of Keycloak 26.6
Red Hat
Red Hat build of Keycloak 26.6
Red Hat
Red Hat build of Keycloak 26.6.6
Red Hat
Red Hat JBoss Enterprise Application Platform Expansion Pack
Red Hat
Red Hat Single Sign-On 7
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability exists in the reset-credentials flow of the keycloak-services component, which is the core identity and access management engine in Red Hat build of Keycloak. The flaw allows an unauthenticated remote attacker to force the password reset process for any user without clicking the required email verification link. The root cause is improper state validation in the reset-credentials authentication flow. Exploitation results in the attacker gaining full access to target user accounts by directly setting new credentials. The vulnerability has a CVSS v3.1 base score of 9.1 (critical) with network attack vector, low complexity, no privileges or user interaction required, and high confidentiality and integrity impacts. Red Hat has published a security advisory and released a fixed version 26.6.6 that addresses this issue.
Potential Impact
An unauthenticated attacker can bypass the email verification step in the password reset process and reset passwords for any user account. This leads to complete account takeover, compromising confidentiality and integrity of user accounts. There is no impact on availability. The vulnerability allows full control over user identities without requiring any authentication or user interaction.
Mitigation Recommendations
Red Hat recommends upgrading to the fixed version 26.6.6 of Red Hat build of Keycloak as soon as possible. As a temporary mitigation, if immediate upgrade is not feasible, administrators can disable the "Forgot password" functionality across all realms via the administration console (Realm settings → Login → Forgot password → Off). This prevents exploitation by blocking the vulnerable password reset flow until a patch can be applied.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-08-05T15:00:40.360Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-18963","vendor":"Red Hat"}]
Threat ID: 6a849468c6e8be03328570de
Added to database: 08/18/2026, 17:20:40 UTC
Last enriched: 09/08/2026, 11:04:43 UTC
Last updated: 10/02/2026, 02:56:34 UTC
Views: 106
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.