Keycloak unauthenticated account takeover via reset-credentials flow bypass

4mnt1 pts0 comments

CVE-2026-18963 Unauthenticated account takeover via reset-credentials flow bypass · Issue #51833 · keycloak/keycloak · GitHub

//voltron/issues_fragments/issue_layout" data-turbo-transient="true" />

Skip to content

Search/

Sign in<br>Sign upAppearance settings

You signed in with another tab or window. Reload to refresh your session.<br>You signed out in another tab or window. Reload to refresh your session.<br>You switched accounts on another tab or window. Reload to refresh your session.

Dismiss alert

{{ message }}

Uh oh!

There was an error while loading. Please reload this page.

keycloak

keycloak

Public

Notifications<br>You must be signed in to change notification settings

Fork<br>8.8k

Star<br>36.3k

CVE-2026-18963 Unauthenticated account takeover via reset-credentials flow bypass #51833

New issue<br>Copy link

New issue<br>Copy link

Closed<br>cve<br>#51844

Closed<br>CVE-2026-18963 Unauthenticated account takeover via reset-credentials flow bypass#51833<br>cve<br>#51844

Copy link

Assignees

Labels<br>backport/mainkind/cveIssues identified as CVEs on third-party dependencies, or issues which Keycloak is not affectedIssues identified as CVEs on third-party dependencies, or issues which Keycloak is not affectedrelease/26.4.15release/26.6.6release/26.7.2severity/criticial

Description

stianst<br>opened on Aug 19, 2026

Issue body actions

Description

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.

Reactions are currently unavailable

Metadata<br>Metadata<br>Assignees

rmartinc

Labels

backport/mainkind/cveIssues identified as CVEs on third-party dependencies, or issues which Keycloak is not affectedIssues identified as CVEs on third-party dependencies, or issues which Keycloak is not affectedrelease/26.4.15release/26.6.6release/26.7.2severity/criticial

Type

cve

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions<br>Open in GitHub Copilot app

You can’t perform that action at this time.

keycloak reset credentials issue unauthenticated flow

Related Articles