Latest Red Hat Keycloak vulnerability: CVE-2026-18963 #
Red Hat disclosed that certain versions of Keycloak are affected by a vulnerability in the reset-credentials authentication flow within the keycloak-services component caused by improper state validation. Successful exploitation allows a remote, unauthenticated attacker to gain full access to any user account by bypassing the email verification step during the password recovery process. The vulnerability has been designated CVE-2026-18963 and has been rated critical with a CVSS score of 9.1.
The following versions are affected
- Red Hat build of Keycloak 26.4: Versions prior to 26.4.15-1 (rhbk/keycloak-operator-bundle) and 26.4-23 (rhbk/keycloak-rhel9, rhbk/keycloak-rhel9-operator)
- Red Hat build of Keycloak 26.6: Versions prior to 26.6.6-1 (rhbk/keycloak-operator-bundle) and 26.6-12 (rhbk/keycloak-rhel9, rhbk/keycloak-rhel9-operator)
What is Red Hat Keycloak? #
Red Hat Keycloak is an open-source enterprise software platform that provides centralized authentication, single sign-on (SSO), and access management for web applications and microservices.
What is the impact? #
Successful exploitation of this vulnerability would allow a remote, unauthenticated attacker to achieve full account takeover, granting unauthorized access to sensitive organization systems and user data.
Are updates or workarounds available? #
Users are encouraged to update to the latest version as quickly as possible:
- Red Hat build of Keycloak 26.4: Upgrade to version 26.4.15-1 (rhbk/keycloak-operator-bundle), 26.4-23 (rhbk/keycloak-rhel9, rhbk/keycloak-rhel9-operator), or later.
- Red Hat build of Keycloak 26.6: Upgrade to version 26.6.6-1 (rhbk/keycloak-operator-bundle), 26.6-12 (rhbk/keycloak-rhel9, rhbk/keycloak-rhel9-operator), or later.
How to find potentially vulnerable systems with runZero #
From the Software Inventory, use the following query to locate systems running potentially vulnerable software:
vendor:="Red Hat" AND product:="Keycloak"