VDB
CVE-2026-18963
CVE-2026-18963
PUBLISHED
CVSS 9.1 CRITICAL
Reported by redhat · Published August 18, 2026
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.
Risk Scores
CVSS 3.1
9.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4.15-1 |
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4-23 |
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4-23 |
| Red Hat | Red Hat build of Keycloak 26.4.15 | |
| Red Hat | Red Hat build of Keycloak 26.4.15 | |
| Red Hat | Red Hat build of Keycloak 26.6 | 26.6.6-1 |
| Red Hat | Red Hat build of Keycloak 26.6 | 26.6-12 |
| Red Hat | Red Hat build of Keycloak 26.6 | 26.6-12 |
| Red Hat | Red Hat build of Keycloak 26.6.6 | |
| Red Hat | Red Hat build of Keycloak 26.6.6 | |
| Red Hat | Red Hat build of Keycloak 26.6.6 | |
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | |
| Red Hat | Red Hat Single Sign-On 7 | |
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4.15-1, 26.4.15-1, 26.4.15-1 |
| Red Hat | Red Hat build of Keycloak 26.6 | 26.6.6-1 |
| Maven | org.keycloak:keycloak-services | 26.0.0 |
| Red Hat | Red Hat build of Keycloak 26.6 | 26.6-12 |
| Red Hat | Red Hat build of Keycloak 26.6 | 26.6.6-1, 26.6.6-1, 26.6.6-1 |
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | |
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4-23, 26.4-23, 26.4-23 |
…and 11 more
Timeline
- Aug 18, 2026 CVE Published
- Aug 19, 2026 Distribution Patch
- Aug 19, 2026 Security Advisory
- Aug 19, 2026 Distribution Patch
- Aug 19, 2026 Security Advisory
- Aug 19, 2026 Distribution Patch
- Aug 19, 2026 Security Advisory
- Aug 19, 2026 Distribution Patch
- Aug 19, 2026 Security Advisory
- Aug 20, 2026 CVE Updated
- Aug 22, 2026 Coalition ESS Score
- Aug 24, 2026 EPSS Score
References
- RHSA-2026:56519 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:56520 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:56523 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:56524 vendor-advisoryx_refsource_REDHAT
- vdb-entryx_refsource_REDHAT
- RHBZ#2511595 issue-trackingx_refsource_REDHAT
- https://nvd.nist.gov/vuln/detail/CVE-2026-18963 advisory
- https://github.com/advisories/GHSA-4gv3-mc9p-5wqc advisory
- https://github.com/keycloak/keycloak/issues/51833 discussion
- https://github.com/keycloak/keycloak/pull/51844 fix
- https://github.com/keycloak/keycloak/commit/dc2d4e524b4dae85aedc87ca28b9e4fa567d56c1 fix