Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Keycloak Password Vulnerability: Critical Update Released

Keycloak Password Vulnerability: Critical Update Released

Posted on August 24, 2026 By CWS

Red Hat, alongside the Keycloak project, has issued a security patch to fix a critical vulnerability in their open-source identity and access management server. This flaw, identified as CVE-2026-18963, permits unauthenticated attackers to take control of any user account by exploiting a password reset mechanism.

Details of the Security Flaw

Rated 9.1 on the CVSS scale, the vulnerability is classified under CWE-640 due to its weak password recovery processes. Users of Keycloak are urged to upgrade to version 26.7.2, released on August 19, 2026. Red Hat customers using Keycloak should update to versions 26.4.15 and 26.6.6 as appropriate.

Although the vulnerability has not been exploited, and no public exploit exists, Red Hat warns of its critical nature. The flaw arises from improper validation during the reset-credentials authentication flow, enabling remote attackers to bypass user interaction requirements.

Exploitation Mechanics

The defect allows attackers to send a specially crafted request to Keycloak’s reset-credentials endpoint. This request moves the authentication session to the password update phase without the usual action token, which is typically emailed to users. Successful exploitation can lead to full account takeovers, even of administrative accounts.

Security researcher Enzo Mongin notes that once an attacker breaches Keycloak, they potentially access other systems integrated with it. Red Hat has released errata that address these issues, affecting standalone server packages and container images.

Mitigation and Future Precautions

For systems that cannot be immediately updated, Red Hat advises disabling the “Forgot password” feature across all realms. This setting can be found in the RHBK administration console under Realm settings, then Login.

Beyond CVE-2026-18963, Keycloak’s 26.7.2 release also fixes seven other vulnerabilities, including a predictable hash flaw in account linking. Previous updates addressed significant issues like SAML identity-provider-initiated broker login bypasses.

Univention reports that its Keycloak deployments are unaffected as they do not utilize the vulnerable password recovery feature. The complete resolution of the flaw remains unclear, with questions about specific configurations at risk still unanswered.

The Hacker News Tags:Authentication, CVE, CVE-2026-18963, Cybersecurity, Exploit, identity management, IT security, Keycloak, Open Source, password reset, Patch, Red Hat, Security, Update, Vulnerability

Post navigation

Previous Post: Microsoft Investigates Windows 11 RGB Issues Post-Update
Next Post: CISOs Face Challenges in Balancing Security and Business Goals

Related Posts

BlueNoroff Targets Crypto Wallets via Phishing on Zoom BlueNoroff Targets Crypto Wallets via Phishing on Zoom The Hacker News
Linux PamDOORa Backdoor Exploits PAM to Steal SSH Credentials Linux PamDOORa Backdoor Exploits PAM to Steal SSH Credentials The Hacker News
AI Network Firewalls: Revolutionizing Cybersecurity AI Network Firewalls: Revolutionizing Cybersecurity The Hacker News
WordPress Vulnerability and SonicWall Exploits Dominate Cyber News WordPress Vulnerability and SonicWall Exploits Dominate Cyber News The Hacker News
HOOK Android Trojan Adds Ransomware Overlays, Expands to 107 Remote Commands HOOK Android Trojan Adds Ransomware Overlays, Expands to 107 Remote Commands The Hacker News
Critical Flaw in AI Platform Writer Poses Security Risks Critical Flaw in AI Platform Writer Poses Security Risks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Isolated-vm Vulnerability Risks JavaScript Security
  • TikTok Settles $400 Million Privacy Case with DOJ
  • AI Threats and Security Vulnerabilities Highlighted This Week
  • Android Malware Targets Car Screens Through Updates
  • Enhancing Application Security in the AI Age

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Isolated-vm Vulnerability Risks JavaScript Security
  • TikTok Settles $400 Million Privacy Case with DOJ
  • AI Threats and Security Vulnerabilities Highlighted This Week
  • Android Malware Targets Car Screens Through Updates
  • Enhancing Application Security in the AI Age

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark