9.1 CVE-2026-18963
Enriched by CISA
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.
https://nvd.nist.gov/vuln/detail/CVE-2026-18963
Categories
CWE-640 : Weak Password Recovery Mechanism for Forgotten Password
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak. Make sure that all input supplied by the user to the password recovery mechanism is thoroughly filtered and validated. Do not use standard weak security questions and use several security questions. Make sure that there is throttling on the number of incorrect answers to a security question. Disable the password recovery functionality after a certain (small) number of incorrect guesses. Require that the user properly answers the security question prior to resetting their password and sending the new password to the e-mail address of record. Never allow the user to control what e-mail address the new password will be sent to in the password recovery mechanism. Assign a new temporary password rather than revealing the original password. password reset functionality for a WordPress plugin allows a brute force attack of the one-time password password reset functionality for a WordPress plugin allows a brute force attack of the one-time password password recovery mechanism for AI developer toolkit does not invalidate the reset password token after it is used, allowing attackers to reuse the token to change passwords of victims web conference product resets passwords to random 8-digit values, allowing brute force attacks by retrieving the hash
References
secalert@redhat.com
AFFECTED (from MITRE)
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat build of Keycloak 26.4 |
|
| Red Hat | Red Hat build of Keycloak 26.4 |
|
| Red Hat | Red Hat build of Keycloak 26.4 |
|
| Red Hat | Red Hat build of Keycloak 26.4.15 | |
| Red Hat | Red Hat build of Keycloak 26.4.15 | |
| Red Hat | Red Hat build of Keycloak 26.6 |
|
| Red Hat | Red Hat build of Keycloak 26.6 |
|
| Red Hat | Red Hat build of Keycloak 26.6 |
|
| Red Hat | Red Hat build of Keycloak 26.6.6 | |
| Red Hat | Red Hat build of Keycloak 26.6.6 | |
| Red Hat | Red Hat build of Keycloak 26.6.6 | |
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | |
| Red Hat | Red Hat Single Sign-On 7 | |
| © 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. | ||
CPE
| cpe | start | end |
|---|
REMEDIATION
EXPLOITS
Exploit-db.com
| id | description | date | |
|---|---|---|---|
| No known exploits | |||
POC Github
| Url |
|---|
| No known exploits |
Other Nist (github, ...)
| Url |
|---|
| No known exploits |
CAPEC
Common Attack Pattern Enumerations and Classifications
| id | description | severity |
|---|---|---|
| 50 | Password Recovery Exploitation |
High |
Cybersecurity needs ?
Strengthen software security from the outset with our DevSecOps expertise
Integrate security right from the start of the software development cycle for more robust applications and greater customer confidence.
Our team of DevSecOps experts can help you secure your APIs, data pipelines, CI/CD chains, Docker containers and Kubernetes deployments.
