All CVEs
Vulnerability intelligence

CVE-2026-18963

Red Hat Red Hat build of Keycloak 26.4 CWE-640

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.

CVSS Score
9.1
Critical
EPSS — Exploit Probability
3.2%
Riskier than 88% of all CVEs · checked 2026-10-04
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
NVD entry PoC / advisory

5 articles across 2 outlets · first covered Aug 20, 2026 · latest Sep 22, 2026

Coverage timeline

Related CVEs — Red Hat