A critical vulnerability in Keycloak , the popular open-source identity and access management system, allows unauthorized remote attackers to take complete control of any user account — including administrative accounts. Red Hat and the Keycloak development team have released emergency security updates to address the issue, which is located in the password reset flow . The vulnerability has been assigned the identifier CVE-2026-18963 and is rated 9.1 on the CVSS scale .

Keycloak is widely used by organizations worldwide for centralized login management, Single Sign-On (SSO) and user authentication to applications and services. The vulnerability is located in the keycloak-services and specifically in the reset-credentials, where the state manager fails to properly enforce the email verification step, which is normally required before a password reset can be performed. The vulnerability has been classified as CWE-640 (Weak Password Recovery Mechanism for Forgotten Password).
According to Red Hat, the root cause is “improper state validation within the reset-credentials authentication flow,” the sequence that Keycloak executes when a user requests a password reset. An attacker can send a specially crafted request to the reset-credentials, causing the authentication session to jump directly to the password update phase, without requiring the action token that is normally emailed to the actual user.
CVE-2026-18963: How the Keycloak vulnerability works
The CVE-2026-18963 is particularly worrisome because it requires no interaction with the victim user and can be performed remotely by an unauthorized attacker. In practice, the attacker exploits a flaw in the state management of the password reset flow: instead of following the normal process — reset request → send email with a unique link → verify → change password — he completely bypasses the email verification step and goes directly to the final step of setting a new password.
The result is devastating: the attacker can set a new password for any account, gaining complete control . If the target is an administrative account, the breach extends to the entire system. Escape researcher Enzo Mongin , commenting on a similar vulnerability in Keycloak in July, pointed out that an attacker who breaches the server doesn’t stop at Keycloak — “ he gets into everything behind it .” This means that the breach can extend to all applications and services that rely on Keycloak for authentication.
It is worth noting that MFA (Multi-Factor Authentication) alone is not sufficient protection against this vulnerability. The reason is that the attack completely bypasses the normal login process — it does not try to guess or steal credentials, but replaces them directly through the recovery flow. So, even if an account is protected with MFA, an attacker can set a new password and then gain access without having to bypass the second authentication factor.

Keycloak: Available updates and workaround
Red Hat issued four errata on August 18, 2026 (RHSA-2026:56519, RHSA-2026:56520, RHSA-2026:56523 and RHSA-2026:56524), covering the standalone server packages and container images for two streams of Red Hat Build of Κkeycloak (RHBK ). The stable releases are as follows: Red Hat Build of Κkeycloak 26.4 is not affected by operator bundle 26.4.15-1 and images rhbk/keycloak-rhel9 and rhbk/keycloak-rhel9-operator 26.4-23. Red Hat Build of Κkeycloak 26.6 is not affected by operator bundle 26.6.6-1 and containers keycloak-rhel9 and operator 26.6-12. The upstream Keycloak was fixed in version 26.7.2, released on August 19, 2026.
See also: CVE-2026-60236: Critical RCE in Oracle Coherence (CVSS 9.8) – what to do now
For deployments that cannot be updated immediately, Red Hat has published a temporary workaround : disabling the “Forgot password” feature across all realms . In the RHBK management console , the setting is located under the Realm settings → Login → Forgot password menu . Red Hat emphasizes that the setting must be applied to each realm separately and that users should upgrade to the fixed version as soon as possible.
There is no evidence so far that the vulnerability has been actively exploited, however proof-of-concept activity was reported shortly after the disclosure, which increases the risk of opportunistic attacks.
CVE -2026-18963 was one of eight CVEs fixed in the Keycloak 26.7.2 release notes . The same release also addressed CVE-2026-15571 , an account-linking hash that allows account takeover via a malicious OpenID Connect (OIDC) client. Two weeks earlier, on August 5, 2026 , Keycloak 26.7.1 had fixed twelve CVEs , including a SAML identity-provider-initiated broker login vulnerability that bypassed a link-only restriction, as well as a default dynamic client registration policy that allowed role spoofing via user property mappers.
The fact that so many vulnerabilities are being addressed in successive versions of Keycloak suggests that the development team is in an intensive security audit cycle. However, it also means that organizations using Keycloak should closely monitor updates and apply patches without delay, especially for deployments that are exposed to the internet.
Practical recommendations for Keycloak users
Organizations using Keycloak or Red Hat Builds of Keycloak should take immediate action. First and foremost, upgrading to the patched versions (26.4.15, 26.6.6 , or 26.7.2) is absolutely necessary. If an immediate upgrade is not possible, disabling the “Forgot password” feature across all realms is an effective interim measure. In addition, it is recommended to review the logs for unusual password reset activity, particularly repeated reset attempts or resets without normal user follow-up.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: CVE-2026-56163: Critical EoP in Azure Kubernetes Service (AKS) – Mitigated by Microsoft
In case of suspected breach, it is recommended to immediately cancel suspicious sessions and force password changes for affected accounts. Particular attention should be paid to internet-facing identity providers, customer portals, and any deployment that exposes the reset-credentials to the public internet. Finally, it is important to remember that MFA is a necessary but not sufficient measure against this particular vulnerability, as the attack completely bypasses the normal login process.

According to The Hacker News, there is no evidence of exploitation of the vulnerability so far, but the existence of proof-of-concept code and the critical nature of the vulnerability make it imperative to take immediate action. The CVE-2026-18963 is a reminder that identity management systems are critical infrastructure points — if they are compromised, an attacker gains access to everything they protect. Immediate application of available patches is the only effective response.
