Dossier
CVE-2026-18963
Coverage of CVE-2026-18963 in the Nexus archive.
- Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
Red Hat and the Keycloak project released patches addressing a critical security flaw in the open-source identity and access management server. This vulnerability, identified as CVE-2026-18963, could allow an unauthenticated remote attacker to take over any user account by forcing a password reset. Red Hat assigned this flaw a 9.1 rating on the CVSS scoring system.