Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4358 articles · 196331 vulns · 36/41 feeds (7d)
← Back to list
9.1
CVE-2026-18963PATCHED
red hat · red hat build of keycloak

Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass

Description

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.

Affected Products

VendorProductVersions
red hatred hat build of keycloak—

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourcekeycloakcert_advisory90%

References

  • https://access.redhat.com/errata/RHSA-2026:56519(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:56520(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:56523(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:56524(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/security/cve/CVE-2026-18963(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2511595(issue-tracking, x_refsource_REDHAT)

Related News (2 articles)

Tier B
BSI Advisories4d ago
[NEU] [hoch] Keycloak: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB5d ago
CVE-2026-18963 | Red Hat Build of Keycloak keycloak-services password recovery
→ No new info (linked only)
CVSS 3.19.1 NONE
CISA KEV❌ No
Actively exploited❌ No
Patch available
26.4-2326.4.15-126.6-1226.6.6-1
CWECWE-640
PublishedAug 18, 2026
Last enriched5d ago
Trending Score26
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-13595EXP
Util-linux: util-linux: heap use-after-free in libblkid nested partition probing
Trending: 36
NONECVE-2026-18917EXP
Libvirt: integer overflow in nodegetfreepages rpc handler leading to heap buffer overflow
Trending: 35
NONECVE-2026-17523EXP
Kernel: can:bcm: arbitrary kernel code execution leading to escalate privileges
Trending: 33
MEDIUMCVE-2026-73199EXP
Ipa: freeipa: null pointer dereference in `ipa-enrollment` extended operation (`join_oid`) via missing request value
Trending: 23
NONECVE-2026-77176
Kata-containers: insufficient validation of createcontainer mount and storage rules in genpolicy
Trending: 23

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 18, 2026
Discovered by ZDM
Aug 18, 2026
Patch Available
Aug 20, 2026