Back to advisories

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Critical flaw in Keycloak (CVE-2026-18963, CVSS 9.1) allows unauthenticated attackers to reset any user password and take over accounts due to improper state validation in the password recovery flow. Any organization running Keycloak without patches is immediately at risk of account takeover on all user accounts.

CRITICALAdvisoryAug 24, 2026
Action required
Immediately patch all Keycloak instances to patched versions or disable the 'Forgot password' functionality. Hunt for POST requests to password reset endpoints from unauthenticated sources and monitor for unusual password reset activity in the past 30 days.
Affected products
KeycloakRed Hat