URL has been copied successfully!
Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset.The vulnerability, assigned the CVE identifier CVE-2026-18963, is rated 9.1 on the CVSS scoring system by Red Hat, which acts as

First seen on thehackernews.com

Jump to article: thehackernews.com/2026/08/critical-keycloak-password-reset-flaw.html

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link