TL;DR

what: Red Hat and the Keycloak project patched CVE-2026-18963, an improper state validation bug in the reset-credentials authentication flow that lets an unauthenticated remote attacker jump straight to the password update phase without the emailed action token.

impact: Successful exploitation is a full takeover of any account on the server, including administrative accounts, and everything sitting behind Keycloak as its identity provider inherits that compromise.

fix: Upgrade to upstream Keycloak 26.7.2 (released August 19, 2026) or Red Hat build of Keycloak 26.4.15 and 26.6.6, and if you cannot patch immediately, turn off Forgot password under Realm settings, then Login, in every realm.

who: Any organization running Keycloak or Red Hat build of Keycloak with the forgotten-password feature enabled on an internet reachable login endpoint.