What is CVE-2026-18963?
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.
Timeline
- 2026-08-18Published to the U.S. National Vulnerability Database (NVD)
- 2026-08-20NVD record last updated
Affected product
See advisory
Remediation Steps
- Apply Red Hat security patch for Keycloak immediately
- Verify that password reset flows require proper authentication
- Audit recent account activity and password reset requests
- Consider implementing additional MFA controls for sensitive accounts
References
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 4 of August 2026 (August 24 – 30)
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.