Weak Password Recovery Mechanism for Forgotten Password in Keycloak - CVE-2026-18963

 

Weak Password Recovery Mechanism for Forgotten Password in Keycloak - CVE-2026-18963

Published: September 1, 2026


Vulnerability identifier: #VU146635
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-18963
CWE-ID: CWE-640
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to take over arbitrary user accounts.

The vulnerability exists due to a weak password recovery mechanism in the reset-credentials flow of the keycloak-services component when handling password reset requests. A remote attacker can bypass the required email verification link and set new credentials to take over arbitrary user accounts.


Affected software

Keycloak
Red Hat build of Keycloak

How to mitigate CVE-2026-18963

Install security update from vendor's website.

Keycloak - addressed in versions 26.4.15, 26.6.6, 26.7.2
Red Hat build of Keycloak - update to 26.4.15

External References

Related Security Bulletins