top of page

Critical Keycloak vulnerability enables remote account takeover: What you need to know

A concerning security vulnerability has been discovered in Keycloak, a popular open-source Identity and Access Management (IAM) solution. This flaw allows remote attackers to hijack any account on the system without requiring user interaction or valid credentials.

Threat level of CVE-2026-18963

Tracked as CVE-2026-18963, this vulnerability has been assigned a CVSS score of 9.1/10 (Critical) by Red Hat. Classified under CWE-640, the flaw stems from a weakness in the password recovery mechanism used when users forget their login credentials.

If successfully exploited, an attacker can force the system to reset passwords and gain full control over any account, including high-privileged administrator accounts.

As of August 24, 2026, there is no evidence indicating that public exploit code has been released or that the flaw has been exploited in the wild. The vulnerability was discovered and reported by cybersecurity researcher James Paremain. Previously, when assessing Keycloak's security boundary, researcher Enzo Mongin from Escape noted that once the server's defenses are breached, attackers can potentially pivot deep into the entire backend infrastructure.

How the vulnerability works

The root cause lies in improper state handling within the reset-credentials execution flow - the sequence Keycloak uses to process password recovery requests.

Under normal circumstances, the system requires an action token sent via email to verify the user's identity. However, an attacker can send a specially crafted request to the reset-credentials endpoint. By doing so, the system is tricked into jumping straight to the password update phase, bypassing the email action token verification step entirely.

Update guidance and risk mitigation measures

To secure their systems, administrators are strongly advised to upgrade or apply mitigation measures immediately. Below is a summary table of recommended fixes per product version:

Product category

Recommended action

Safe version

Details & Notes

Keycloak (Open source)

Full upgrade

26.7.2

Released on August 19, 2026

Red Hat build of Keycloak (RHBK) - 26.4 Stream

Apply patch update

26.4.15

Includes operator bundle 26.4.15-1 and corresponding container image 26.4-23

Red Hat build of Keycloak (RHBK) - 26.6 Stream

Apply patch update

26.6.6

Includes operator bundle 26.6.6-1 and corresponding container image 26.6-12

Systems unable to upgrade immediately

Temporary workaround: Disable forgot password

N/A

Navigate to Realm settings -> Login -> disable "Forgot password" across all realms

Technical considerations and key takeaways

Keycloak version 26.7.2 addresses not only CVE-2026-18963 but also fixes seven other vulnerabilities, including CVE-2026-15571 - an issue involving predictable account-linking state strings via malicious OIDC applications. Prior to this, on August 5, 2026, version 26.7.1 patched 12 other security flaws related to SAML authentication and client registration policies.

Currently, security advisories on GitHub and the NVD do not yet contain complete details regarding the full list of affected downstream products (such as Red Hat Single Sign-On 7 or Red Hat JBoss EAP Expansion Pack). Additionally, published documentation has not clarified whether the update completely addresses all aspects of the issue, nor has it confirmed whether the flaw impacts all realms with the "forgot password" feature enabled or only specific workflow configurations.

Proactively reviewing configurations and upgrading to patched versions is the most critical step right now to safeguard your organization's identity management infrastructure.

Reference: The Hacker News

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
Logo-Zalo-Arc.webp
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page