External risk intelligence

Keycloak Keycloak-Services Password Reset Flaw Allows Account Takeover.

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-18963

Keycloak is an identity and access management solution designed to be public-facing to facilitate user authentication, password resets, and account management services for web applications and APIs. Its primary role involves exposing these identity services to the internet, making this vulnerability directly reachable in standard, intended deployments.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in a core identity and access management component, potentially allowing unauthorized individuals to reset user passwords and gain control of accounts without proper verification. This impacts systems relying on this component for secure user authentication.

  • Unauthenticated attackers can bypass password reset verification.
  • Compromised accounts can lead to unauthorized access.
  • Confirm relevance and exposure of this identity management flaw.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by targeting the password reset feature of Keycloak services. This flaw allows them to bypass the email verification step, enabling them to directly set new credentials for any user. The attacker can then gain unauthorized access to the compromised user accounts.

  • No authentication required for attacker.
  • Attacker forces password reset.
  • Attacker takes over user accounts.

Live Threat

Current exploitation, exposure, and threat context

A flaw in the password reset process of the keycloak-services component could allow an unauthenticated attacker to bypass email verification and directly set new credentials for any user account. This could lead to an attacker gaining full control over compromised user accounts.

  • User accounts.
  • Bypassing email verification.
  • Full account takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in Keycloak's password reset process requires immediate attention from teams managing identity and access. Application owners, platform teams, and potentially the vendor-management team should collaborate to identify all instances of Keycloak, assess their exposure, and prioritize remediation. The first practical step is to confirm where Keycloak is deployed, determine its reachability and business criticality, and assign ownership for the affected instances before planning any necessary actions.

  • Identify Keycloak instances and owners.
  • Verify user account reset exposure.
  • Plan coordinated remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Red Hat Build of Keycloak and the keycloak-services component?

Red Hat Build of Keycloak is an identity and access management solution that secures web applications and APIs by handling user authentication and credentials. The keycloak-services component acts as the underlying engine responsible for these core tasks, including processing password reset requests and managing user session security.

What is the vulnerability in CVE-2026-18963?

This vulnerability is classified as CWE-640, which refers to a weakness where an application fails to properly verify the authenticity of a password reset request. In this specific case, the mechanism meant to confirm a user's identity via email is flawed, allowing unauthorized changes to account credentials.

How can an attacker trigger this password reset flaw?

An attacker triggers this by interacting with the password reset flow directly, bypassing the requirement to click a verification link sent to the user's email. Simply making a request to reset an account's password is sufficient; the vulnerability is not triggered by legitimate user actions or normal password changes.

Is my instance of Keycloak at risk?

According to Halo Surface Signal, this vulnerability is highly relevant because Keycloak is frequently deployed as a public-facing service to allow users to manage their own passwords from the internet. If your instance is reachable via the public web, it is directly exposed to this flaw, making it a priority for assessment.

How should I respond to this Keycloak vulnerability?

Begin by inventorying all deployed instances of Keycloak within your infrastructure to confirm which are active and their respective owners. Once identified, evaluate whether these instances are reachable from the internet, as public-facing services are at the highest risk. Coordinate with your team to prioritize these instances for updates once official patches are available.

References