• Sources: Red Hat CVE page, NVD, RHSA-2026:56519, discussion
  • Summary: CVE-2026-18963 lets an unauthenticated attacker complete a Keycloak password reset without possessing the verification link. The CVE was published 2026-08-18 and is rated CVSS 9.1, with errata shipped 2026-08-18 and 2026-08-20. Red Hat lists Red Hat build of Keycloak 26.4 as affected with the fix in 26.4.15 and container 26.4-23, Red Hat build of Keycloak 26.6 as affected with the fix in 26.6.6-1 and container 26.6-12, Red Hat JBoss EAP Expansion Pack as affected, and Red Hat Single Sign-On 7 as unaffected. Red Hat's mitigation section gives turning Forgot password off across all realms, under Realm settings and Login, as a temporary measure for deployments that cannot patch. NVD's CISA-ADP SSVC entry dated 2026-08-20 records exploitation as none, and no cited source records a public exploit.
  • Why it matters: Keycloak is the identity layer in front of other systems, so an unauthenticated account takeover at CVSS 9.1 is worth patching on the fixed versions above or disabling password reset until it is done.
  • Follow-up: Track advisories from downstream Keycloak distributions and managed identity providers.

send feedback on this story