CVE-2026-18963 Unauthenticated account takeover via reset-credentials flow bypass · Issue #51833 · keycloak/keycloak · GitHub
//voltron/issues_fragments/issue_layout" data-turbo-transient="true" />
Skip to content
Search/
Sign in<br>Sign upAppearance settings
You signed in with another tab or window. Reload to refresh your session.<br>You signed out in another tab or window. Reload to refresh your session.<br>You switched accounts on another tab or window. Reload to refresh your session.
Dismiss alert
{{ message }}
Uh oh!
There was an error while loading. Please reload this page.
keycloak
keycloak
Public
Notifications<br>You must be signed in to change notification settings
Fork<br>8.8k
Star<br>36.3k
CVE-2026-18963 Unauthenticated account takeover via reset-credentials flow bypass #51833
New issue<br>Copy link
New issue<br>Copy link
Closed<br>cve<br>#51844
Closed<br>CVE-2026-18963 Unauthenticated account takeover via reset-credentials flow bypass#51833<br>cve<br>#51844
Copy link
Assignees
Labels<br>backport/mainkind/cveIssues identified as CVEs on third-party dependencies, or issues which Keycloak is not affectedIssues identified as CVEs on third-party dependencies, or issues which Keycloak is not affectedrelease/26.4.15release/26.6.6release/26.7.2severity/criticial
Description
stianst<br>opened on Aug 19, 2026
Issue body actions
Description
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.
Reactions are currently unavailable
Metadata<br>Metadata<br>Assignees
rmartinc
Labels
backport/mainkind/cveIssues identified as CVEs on third-party dependencies, or issues which Keycloak is not affectedIssues identified as CVEs on third-party dependencies, or issues which Keycloak is not affectedrelease/26.4.15release/26.6.6release/26.7.2severity/criticial
Type
cve
Projects
No projects
Milestone
No milestone
Relationships
None yet
Development
No branches or pull requests
Issue actions<br>Open in GitHub Copilot app
You can’t perform that action at this time.