Vulnerability intelligence
CVE-2026-18963
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.
CVSS Score
9.1
Critical
EPSS — Exploit Probability
3.2%
Riskier than 88% of all CVEs · checked 2026-10-04
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
5 articles across 2 outlets · first covered Aug 20, 2026 · latest Sep 22, 2026
Coverage timeline
-
CISA Warns of Critical Siemens Industrial Edge Account Takeover Flawwww.cisa.gov · Sep 22, 2026
-
HCL BigFix flaws expose tenant data and admin accountssecurityonline.info · Sep 18, 2026
-
Siemens Flaws Let Attackers Hijack Accounts and Gain Root Accesssecurityonline.info · Sep 9, 2026
-
Keycloak fixes critical CVE-2026-18963 password reset bypass flawsecurityonline.info · Aug 21, 2026
-
Red Hat patches CVE-2026-66780, blocking Kubernetes MITM risksecurityonline.info · Aug 20, 2026