NPM · AUGUST 2026 · CONFIRMED

Critical Keycloak Password Reset Flaw: CVE-2026-18963 Details

Severity
CRITICAL
CVSS
9.1
Affected component
keycloak-services (npm)
Patched version
Not yet available
CVE-2026-18963

A critical vulnerability in the reset-credentials flow of the keycloak-services component allows unauthenticated attackers to force password resets for any user.

What happened

A critical flaw has been identified in the reset-credentials flow of the keycloak-services component, which is integral to Red Hat Build of Keycloak's identity and access management. This vulnerability, tracked as CVE-2026-18963, enables an unauthenticated attacker to initiate the password reset process for any user account without requiring the user to click the email verification link. This can lead to the attacker gaining full control over the affected user accounts by setting new credentials directly.

The vulnerability was first flagged on August 18, 2026, and confirmed on August 25, 2026. It has been rated 9.1 on the CVSS scale, indicating a critical severity level. Red Hat and the Keycloak project have released patches to address this issue. Users of upstream Keycloak are advised to update to version 26.7.2, while customers running Red Hat build of Keycloak (RHBK) should apply updates for versions 26.4.15 and 26.6.6.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If keycloak-services is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using the keycloak-services component in your environment, you may be affected. Consult the primary sources for the latest information on affected versions.

What should I do right now?

Pin to a non-affected version of keycloak-services or upgrade to a patched version once available and rotate any secrets in affected environments.

Has this been exploited in the wild?

There is no evidence that the flaw has been exploited in the wild as of August 24, 2026.

Where can I find more information about the patches?

Consult the primary sources provided for detailed information on the patches and updates.

Sources

Join the 0Day waitlist →

← Back to all threats