>

Keycloak CVE-2026-18963: Unauthenticated Account Takeover via Password Reset (CVSS 9.1)

Keycloak's reset-credentials flow skips its own email action token: an unauthenticated attacker can set a new password on any account, including admins. CVSS 9.1, fixed in 26.7.2 - patch guide, detection hunting, and the temporary mitigation inside.

Continue ReadingKeycloak CVE-2026-18963: Unauthenticated Account Takeover via Password Reset (CVSS 9.1)
>