CVE-2026-18963
CRITICAL(9.1)CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- CVSS 9.1 — Kritisch
Erwähnungen (letzte 60 Tage)
EPSS-Score
3.2%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
9.1
Technische Schwere
SecBoard-Einordnung
CVE-2026-18963 beschreibt eine kritische Schwachstelle im Reset-Credentials-Flow der keycloak-services Komponente, dem Kern der Identitäts- und Zugriffsverwaltung in Red Hat Build of Keycloak. Diese ermöglicht es einem nicht authentifizierten Angreifer, den Passwort-Reset-Prozess für beliebige Benutzer zu erzwingen, ohne die erforderliche E-Mail-Verifizierungsverknüpfung anklicken zu müssen. Die direkte Festlegung neuer Anmeldeinformationen kann zur vollständigen Übernahme von Benutzerkonten führen.
KI-gestützte Einordnung auf Basis der NVD-Daten.
Beschreibung
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.
GitHub Advisories
Keycloak: Unauthenticated account takeover via reset-credentials flow bypass
Referenzen
- https://access.redhat.com/errata/RHSA-2026:56519
- https://access.redhat.com/errata/RHSA-2026:56520
- https://access.redhat.com/errata/RHSA-2026:56523
- https://access.redhat.com/errata/RHSA-2026:56524
- https://access.redhat.com/security/cve/CVE-2026-18963
- https://bugzilla.redhat.com/show_bug.cgi?id=2511595
- https://cert-portal.siemens.com/productcert/html/ssa-503852.html