Security vulnerabilities have been discovered in the identity and access management system Keycloak, which attackers can exploit, for example, to take over accounts. With an updated software version, the developers are closing seven partly critical security vulnerabilities.

In the release announcement for Keycloak 26.7.2, there is a reference to the serious security vulnerability CVE-2026-18963 (CVSS 9.1, Risk “critical”), which allows unauthenticated attackers from the network to take over accounts in the system. They only need to know a username or an email address and can request a password reset for any user, including administrators. And without ever having received the password reset email, they can then set any password, as can be seen from the Proof-of-Concept repository.

Red Hat in particular has published four security advisories on this, which, however, only list the vulnerability or the different new versions and images (26.4.15 Images Security Update, 26.4.15 Security Update, 26.6.6 Images Security Update, 26.6.6 Security Update). In addition to the vulnerability that can be exploited for account takeover, the programmers are closing further security vulnerabilities in version 26.7.2, for which Red Hat has partially backported the fixes.