Key details

  1. Red Hat rates CVE-2026-18963 Critical with CVSS 9.1.
  2. Attack vector is network; attack complexity is low; no privileges or user interaction are required.
  3. The flaw bypasses the email-verification step in Keycloak’s reset-credentials flow and allows new credentials to be set for a target account.
  4. Upstream Keycloak 26.7.2, released August 19, includes the security fix.
  5. Red Hat Build of Keycloak fixes include supported 26.4.15 and 26.6.6 updates.
  6. Red Hat’s temporary mitigation is to disable `Forgot password` under Realm settings → Login for every realm.
  7. The 26.7.2 security release also fixed other authorization/account-linking issues, including CVE-2026-15571.
  8. Public PoC/scanner material exists. One independent vendor reports honeypot exploitation attempts, but CISA has not added the CVE to KEV at the time of this dossier.

What builders should take away

  1. Upgrade vulnerable upstream Keycloak deployments to 26.7.2 or later; Red Hat customers should apply the fixed build for their supported stream.
  2. If patching cannot happen immediately, disable Forgot Password in every realm as Red Hat recommends, and communicate the temporary recovery change to users/support staff.
  3. Prioritise internet-facing realms and high-value accounts because the exploit path needs no authentication or victim interaction.
  4. Review password-reset events, credential changes and unusual account activity from the exposure window; a successful takeover may look like legitimate credential replacement rather than malware on the host.
  5. Inventory all applications and administrative systems that trust the same Keycloak realm so incident-response scope reflects the identity account’s real permissions.
  6. Do not rely on the absence of a CISA KEV entry as proof that exploitation is not occurring; public PoCs and third-party honeypot claims materially change practical risk.

What changed

Keycloak 26.7.2, released August 19, 2026, fixed CVE-2026-18963 in the reset-credentials flow. Red Hat says improper state validation allowed an unauthenticated remote attacker to complete password recovery without the required email-verification link and directly set new credentials for a target user. Red Hat rates the vulnerability Critical with CVSS 9.1 (network-accessible, low complexity, no privileges and no user interaction). Red Hat Build of Keycloak fixes were shipped for supported 26.4 and 26.6 lines, including 26.4.15 and 26.6.6. If an immediate upgrade is impossible, Red Hat recommends disabling the Forgot Password feature in every realm. Public exploit/PoC material appeared shortly after disclosure; at least one independent security vendor says it observed exploitation attempts in honeypot telemetry, although the CVE is not currently listed in CISA’s Known Exploited Vulnerabilities catalog.

Why it matters

Keycloak often sits in front of multiple applications, APIs and administrative systems, so compromising one identity account can have a much larger blast radius than exploiting a feature inside a single app. The vulnerable path also uses a normal account-recovery feature that many deployments expose publicly. Teams should therefore treat this as an identity-plane patch rather than wait for application-specific indicators. Because proof-of-concept tooling is public, internet-facing deployments have a stronger reason to patch quickly and review logs or account state from the exposure window.

The flaw turns password recovery into an unauthenticated account-takeover path

The reset flow is supposed to require the user to follow a verification link delivered by email before new credentials are accepted. Red Hat says improper state validation allowed an attacker to bypass that requirement and drive the reset process directly, with no existing login or victim click required.

The correct fix is an upgrade, not a WAF rule

Keycloak shipped the upstream fix in 26.7.2, while Red Hat published patched builds for supported product lines. The vendor’s fallback mitigation is operationally blunt but clear: disable Forgot Password across all realms until the deployment can be upgraded.

Public exploitability has increased since the initial disclosure

Initial independent reporting on August 24 said there was no evidence of exploitation and no verified public exploit at that point. Public PoC and scanner material appeared quickly afterward. A security vendor, Previdian, says its honeypots observed exploitation attempts beginning August 25; that claim is independent telemetry rather than a Red Hat or CISA confirmation of compromised production systems.

Identity-server compromise can cross application boundaries

Keycloak often provides authentication for many services. An attacker who resets a privileged or broadly authorized account can inherit whatever access that identity already has, so incident review should consider connected applications and administrative roles rather than only the Keycloak host.

The same release contains several other security fixes

Keycloak 26.7.2 also lists fine-grained admin permission bypasses, secret disclosure and a separate predictable account-linking flaw capable of account takeover. Teams that are behind on the 26.7 line therefore gain more than one security fix by upgrading.

What to watch next

  • Whether CISA or Red Hat later confirms active exploitation or adds the vulnerability to a known-exploited catalog.
  • Additional forensic guidance or indicators for detecting successful password-reset abuse.
  • Whether downstream Keycloak distributions publish different fixed-version mappings.
  • Follow-up disclosures from the same August security batch, especially account-linking or fine-grained-admin bypasses.
  • Whether organisations report cross-application compromise through accounts managed by a shared vulnerable realm.

Still unclear

  • Red Hat confirms the vulnerability and severity but does not state that it has observed exploitation in the wild.
  • Previdian’s exploitation observation is its own honeypot telemetry and is not equivalent to a vendor-confirmed production compromise.
  • CISA has not listed CVE-2026-18963 in the Known Exploited Vulnerabilities catalog at the time of writing.
  • Affected-version boundaries can differ between upstream Keycloak and Red Hat Build of Keycloak because Red Hat backports fixes.

Sources

Direct reading behind this dossier.

4 sources
CVE-2026-18963
Red Hat primary security advisory

Authoritative CVE description, Critical 9.1 rating, attack preconditions and temporary mitigation.

Keycloak 26.7.2 released
Keycloak primary release notes

Primary upstream release showing CVE-2026-18963 and the related security fixes included in 26.7.2.

CVE-2026-18963 exploitation tracking
Previdian independent security telemetry

Independent claim of honeypot exploitation attempts and public PoC availability; treated as vendor telemetry, not Red Hat/CISA confirmation.

Discussion

Discussion is reader-contributed. Comments are not part of the BTN dossier or its editorial evidence.

0 visible comments

Join the discussion

Keep comments useful and relevant. Reader contributions may be moderated and are not BTN editorial evidence.

Sign in to comment