Critical Red Hat Keycloak Flaw Lets Unauthenticated Attackers Take Over Any User Account

Red Hat has disclosed a critical vulnerability in the Red Hat Build of Keycloak that could allow unauthenticated remote attackers to take over arbitrary user accounts. Tracked as CVE-2026-18963, the flaw affects the password recovery process and carries a CVSS v3.1 score of 9.1. The vulnerability exists in the reset-credentials flow of the keycloak-services component, […]

This article has been indexed from Cyber Security News

Read the original article: