Critical Keycloak Password Reset Flaw: CVE-2026-18963 Details
- Severity
- CRITICAL
- CVSS
- 9.1
- Affected component
- keycloak-services (npm)
- Patched version
- Not yet available
A critical vulnerability in the reset-credentials flow of the keycloak-services component allows unauthenticated attackers to force password resets for any user.
What happened
A critical flaw has been identified in the reset-credentials flow of the keycloak-services component, which is integral to Red Hat Build of Keycloak's identity and access management. This vulnerability, tracked as CVE-2026-18963, enables an unauthenticated attacker to initiate the password reset process for any user account without requiring the user to click the email verification link. This can lead to the attacker gaining full control over the affected user accounts by setting new credentials directly.
The vulnerability was first flagged on August 18, 2026, and confirmed on August 25, 2026. It has been rated 9.1 on the CVSS scale, indicating a critical severity level. Red Hat and the Keycloak project have released patches to address this issue. Users of upstream Keycloak are advised to update to version 26.7.2, while customers running Red Hat build of Keycloak (RHBK) should apply updates for versions 26.4.15 and 26.6.6.
What to do about it
- Pin to a non-affected version of keycloak-services or upgrade to a patched version once available.
- Rotate any secrets in affected environments immediately.
- Monitor the primary sources for updates on patched versions and further details.
- Ensure that all instances of keycloak-services are updated to the latest secure version as soon as possible.
- Conduct a security audit of all user accounts to check for any unauthorized changes or access.
How 0Day would have caught this
keycloak-services is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using the keycloak-services component in your environment, you may be affected. Consult the primary sources for the latest information on affected versions.
What should I do right now?
Pin to a non-affected version of keycloak-services or upgrade to a patched version once available and rotate any secrets in affected environments.
Has this been exploited in the wild?
There is no evidence that the flaw has been exploited in the wild as of August 24, 2026.
Where can I find more information about the patches?
Consult the primary sources provided for detailed information on the patches and updates.