peter bassill · operator
$ cve CVE-2026-18963 JSON

CVE-2026-18963

9.1
CRITICAL · CVSS 3.1 · EPSS 3.2% (pctl 88)

In your normal cycle

Critical by CVSS (9.1), but no sign of active exploitation.

Description

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.

Scoring

CVSS9.1 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS3.18% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-640
On CISA KEVno
Public exploitnone known
Published2026-08-18
Last modified2026-09-08

References

→ the Explorer  ·  watch your stack  ·  NVD