Critical Keycloak flaw lets attackers take over any account via password reset
A critical flaw in Keycloak, the widely used open-source identity and access management server, lets an unauthenticated attacker take over any account through its password-reset flow. Tracked as CVE-2026-18963, the bug is improper state validation in the reset-credentials flow: a crafted request to the reset endpoint pushes the authentication session straight to the password-update step, so the action token Keycloak normally emails is never required, and the attacker sets new credentials for a chosen user. It needs no user interaction and works against any account, including administrators. Red Hat fixed it in Keycloak 26.7.2 and related releases; there is no confirmed exploitation yet.
- Check
- Upgrade Keycloak to a fixed release such as 26.7.2, and if you ran a vulnerable version, revoke active and offline sessions and rotate client secrets, since tokens may already have been issued.
- Affected
- Organizations running Keycloak with the forgotten-password feature enabled on a vulnerable version (CVE-2026-18963); an unauthenticated attacker can reset and take over any user or admin account without the email verification step.
- Fix
- Patch promptly, then treat exposure as possible account compromise: revoke sessions, rotate accessible client secrets, review identity links and admin permissions, and remember downstream services may hold tokens issued before patching.