9.1 CVE-2026-18963

Enriched by CISA
 

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.
https://nvd.nist.gov/vuln/detail/CVE-2026-18963

Categories

CWE-640 : Weak Password Recovery Mechanism for Forgotten Password
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak. Make sure that all input supplied by the user to the password recovery mechanism is thoroughly filtered and validated. Do not use standard weak security questions and use several security questions. Make sure that there is throttling on the number of incorrect answers to a security question. Disable the password recovery functionality after a certain (small) number of incorrect guesses. Require that the user properly answers the security question prior to resetting their password and sending the new password to the e-mail address of record. Never allow the user to control what e-mail address the new password will be sent to in the password recovery mechanism. Assign a new temporary password rather than revealing the original password. password reset functionality for a WordPress plugin allows a brute force attack of the one-time password password reset functionality for a WordPress plugin allows a brute force attack of the one-time password password recovery mechanism for AI developer toolkit does not invalidate the reset password token after it is used, allowing attackers to reuse the token to change passwords of victims web conference product resets passwords to random 8-digit values, allowing brute force attacks by retrieving the hash

References


 

AFFECTED (from MITRE)


Vendor Product Versions
Red Hat Red Hat build of Keycloak 26.4
  • 26.4.15-1 < * [unaffected]
Red Hat Red Hat build of Keycloak 26.4
  • 26.4-23 < * [unaffected]
Red Hat Red Hat build of Keycloak 26.4
  • 26.4-23 < * [unaffected]
Red Hat Red Hat build of Keycloak 26.4.15
    Red Hat Red Hat build of Keycloak 26.4.15
      Red Hat Red Hat build of Keycloak 26.6
      • 26.6.6-1 < * [unaffected]
      Red Hat Red Hat build of Keycloak 26.6
      • 26.6-12 < * [unaffected]
      Red Hat Red Hat build of Keycloak 26.6
      • 26.6-12 < * [unaffected]
      Red Hat Red Hat build of Keycloak 26.6.6
        Red Hat Red Hat build of Keycloak 26.6.6
          Red Hat Red Hat build of Keycloak 26.6.6
            Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack
              Red Hat Red Hat Single Sign-On 7
                © 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

                CPE

                cpe start end


                REMEDIATION




                EXPLOITS


                Exploit-db.com

                id description date
                No known exploits

                POC Github

                Url
                No known exploits

                Other Nist (github, ...)

                Url
                No known exploits


                CAPEC


                Common Attack Pattern Enumerations and Classifications

                id description severity
                50 Password Recovery Exploitation
                High