Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Keycloak Password Vulnerability: Critical Update Released

Keycloak Password Vulnerability: Critical Update Released

Posted on August 24, 2026 By CWS

Red Hat, alongside the Keycloak project, has issued a security patch to fix a critical vulnerability in their open-source identity and access management server. This flaw, identified as CVE-2026-18963, permits unauthenticated attackers to take control of any user account by exploiting a password reset mechanism.

Details of the Security Flaw

Rated 9.1 on the CVSS scale, the vulnerability is classified under CWE-640 due to its weak password recovery processes. Users of Keycloak are urged to upgrade to version 26.7.2, released on August 19, 2026. Red Hat customers using Keycloak should update to versions 26.4.15 and 26.6.6 as appropriate.

Although the vulnerability has not been exploited, and no public exploit exists, Red Hat warns of its critical nature. The flaw arises from improper validation during the reset-credentials authentication flow, enabling remote attackers to bypass user interaction requirements.

Exploitation Mechanics

The defect allows attackers to send a specially crafted request to Keycloak’s reset-credentials endpoint. This request moves the authentication session to the password update phase without the usual action token, which is typically emailed to users. Successful exploitation can lead to full account takeovers, even of administrative accounts.

Security researcher Enzo Mongin notes that once an attacker breaches Keycloak, they potentially access other systems integrated with it. Red Hat has released errata that address these issues, affecting standalone server packages and container images.

Mitigation and Future Precautions

For systems that cannot be immediately updated, Red Hat advises disabling the “Forgot password” feature across all realms. This setting can be found in the RHBK administration console under Realm settings, then Login.

Beyond CVE-2026-18963, Keycloak’s 26.7.2 release also fixes seven other vulnerabilities, including a predictable hash flaw in account linking. Previous updates addressed significant issues like SAML identity-provider-initiated broker login bypasses.

Univention reports that its Keycloak deployments are unaffected as they do not utilize the vulnerable password recovery feature. The complete resolution of the flaw remains unclear, with questions about specific configurations at risk still unanswered.

The Hacker News Tags:Authentication, CVE, CVE-2026-18963, Cybersecurity, Exploit, identity management, IT security, Keycloak, Open Source, password reset, Patch, Red Hat, Security, Update, Vulnerability

Post navigation

Previous Post: Microsoft Investigates Windows 11 RGB Issues Post-Update
Next Post: CISOs Face Challenges in Balancing Security and Business Goals

Related Posts

AI Voice Cloning Exploit, Wi-Fi Kill Switch, PLC Vulns, and 14 More Stories AI Voice Cloning Exploit, Wi-Fi Kill Switch, PLC Vulns, and 14 More Stories The Hacker News
Iran’s State TV Hijacked Mid-Broadcast Amid Geopolitical Tensions; M Stolen in Crypto Heist Iran’s State TV Hijacked Mid-Broadcast Amid Geopolitical Tensions; $90M Stolen in Crypto Heist The Hacker News
AI Chatbots Lead Users to Cryptojacking Malware Sites AI Chatbots Lead Users to Cryptojacking Malware Sites The Hacker News
How to Deploy AI More Securely at Scale How to Deploy AI More Securely at Scale The Hacker News
Mastra npm Packages Compromised in Supply Chain Attack Mastra npm Packages Compromised in Supply Chain Attack The Hacker News
MuddyWater Intensifies Cyber Attacks in MENA with New Malware MuddyWater Intensifies Cyber Attacks in MENA with New Malware The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Tensorlake npm Package Exploited to Spread Malware
  • Chinese Hackers Exploited Flaws for Email Theft: FBI
  • VirusTotal API Keys Allegedly Sold on Dark Web
  • Fortinet Devices Targeted by FortiBleed Attackers
  • Japan Faces Surge in Data Breaches Due to API and Software Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Tensorlake npm Package Exploited to Spread Malware
  • Chinese Hackers Exploited Flaws for Email Theft: FBI
  • VirusTotal API Keys Allegedly Sold on Dark Web
  • Fortinet Devices Targeted by FortiBleed Attackers
  • Japan Faces Surge in Data Breaches Due to API and Software Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark