Enterprise IT Support • Bangkok & Nationwide

Technology newsroom

Urgent Alert! Critical Keycloak Vulnerability Allows Account Takeover via Forced Password Reset

A critical security vulnerability (CVE-2026-18963) has been discovered in Keycloak, allowing attackers to take over any user account via the password reset function. It has a CVSS score of 9.1, and a patch has been released.

Edited by SyncTech Solution Published Source Original source
A stylized digital padlock icon overlaid on the Keycloak logo, with a red alert symbol indicating a critical security vulnerability.

Key Highlights:
- A vulnerability, CVE-2026-18963, has been discovered in Keycloak, an Open-Source Identity and Access Management system.
- Its severity is critical, with a CVSS score of 9.1, allowing unauthenticated remote attackers to exploit it.
- Attackers can take over any user account via a flaw in the password reset function. Red Hat has already released a patch.

Red Hat and the Keycloak development team have issued an urgent alert regarding a critical security vulnerability in Keycloak software, a widely popular Open-Source Identity and Access Management (IAM) system. The vulnerability is identified as CVE-2026-18963 and has received a high CVSS severity score of 9.1, indicating extreme danger.

Attack Vector
The most concerning aspect of this vulnerability is that it allows unauthenticated remote attackers to gain full control over any user account in a Keycloak-powered system. The method involves exploiting a flaw in the password reset process, enabling attackers to force the system to set a new password for a target account without the account owner's knowledge.

Impact and Risk
An attacker's ability to take over user accounts poses a severe risk, as it can lead to unauthorized access to sensitive data and systems. This could result in data damage, service disruption, and affect the credibility of organizations that rely on Keycloak for their core identity verification.

Remediation and Prevention
To prevent damage, Red Hat and the Keycloak project have already released a patch to fix this vulnerability. We strongly recommend that System Admins and developers who use Keycloak in their systems promptly apply the security patch to mitigate the risk of attacks through this vector.

Are you using Keycloak in your systems? Please check and update the patch immediately!

Let’s build what’s next

Better IT starts with understanding your business.

Tell our engineers what you need and receive an initial recommendation at no cost.