Critical Vulnerability in Red Hat Keycloak

A critical vulnerability CVE-2026-18963 (CVSS score - 9.1) has been discovered in Red Hat's identity access management solution KeyCloak (Red Hat Build of Keycloak), allowing unauthenticated users to reset any system user's password. The flaw is in the password reset procedure accessible via the "Forgot Password" function. It enables an attacker to change any user's password without a key sent to the user's email. No prior system access is required, but knowledge of existing usernames is necessary. More information: https://access.redhat.com/security/cve/cve-2026-18963

This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.

Read original source