securityonline.info 8/21/2026, 12:26:41 PM · external

Keycloak fixes critical CVE-2026-18963 password reset bypass flaw

Keycloak fixes critical CVE-2026-18963 password reset bypass flaw
CyberSIXT Evidence Panel
Primary Source keycloak.org
CISA KEV Not in KEV
Patch Patch Status Unknown

A recent update (Keycloak 26.7.2) released on August 19, 2026, addresses five vulnerabilities, notably the critical CVE-2026-18963, which allows unauthenticated account takeover through a password reset bypass. This flaw has a CVSS score of 9.1, indicating its high severity. Other significant vulnerabilities include CVE-2026-15571, which can be exploited by a malicious OIDC client to take over accounts. Users are urged to apply the latest security updates immediately, as no public exploitation has been confirmed yet.

View Primary Source Via securityonline.info

Article by CyberSIXT