2026-08-19HIGHAn identity provider's account-recovery path is the account-takeover path, and one affected Red Hat product has no fix at all
Red Hat build of Keycloak (keycloak-services), reset-credentials flow bypass letting an unauthenticated attacker complete a password reset without the email-verification click and set new credentials, reaching full account takeover including administrators (CVSS 9.1, Red Hat as CNA; root cause improper state validation). Fixed 2026-08-18 in RHBK 26.4.15 (RHSA-2026:56520) and 26.6.6 (RHSA-2026:56523) plus the matching image and operator errata. Product-state correction (2026-08-24 audit): Red Hat records only two products under package_state, both "Not affected", the JBoss EAP Expansion Pack and Red Hat Single Sign-On 7; no Red Hat product is affected and unfixed.
cve · CVE-2026-18963 single-source
Coverage
1
first 2026-08-19 → last 2026-08-24
Latest activity
2026-08-19
An identity provider's account-recovery path is the account-takeover path, and one affected Red Hat product…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, finance, healthcare · regions: europe
Sources cited
4
2 hosts
Action items (3)
Do-now tasks recorded on the entries about CVE-2026-18963, newest first. Check the date before acting on an older one.
- Upgrade Red Hat build of Keycloak to 26.4.15 on the 26.4 stream or 26.6.6 on the 26.6 stream, and update the matching RHEL 9 / OpenShift container images and operator bundles, patching the keycloak-services package alone leaves a deployment running the old image unfixed.2026-08-19CVE-2026-18963
- If a JBoss Enterprise Application Platform Expansion Pack deployment was scoped as exposed to CVE-2026-18963 and given a compensating control or an open no-fix risk item, close it, Red Hat records that product's keycloak-services package as Not affected, so there is no exposure to mitigate and no erratum to wait for.2026-08-19CVE-2026-18963
- Where Red Hat build of Keycloak 26.4.15 / 26.6.6 cannot be applied immediately, use Red Hat's own documented interim step (administration console, Realm settings, Login, Forgot password, Off) applied to every realm, in preference to blocking the reset path at the reverse proxy.2026-08-19CVE-2026-18963
Defender insights
What each entry about CVE-2026-18963 tells a defender to do, newest first.
Triage
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (2 across 3 tactics)
2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- PersistenceAccount Manipulation
- Privilege EscalationAccount Manipulation
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-08-19/cve-2026-18963-keycloak-reset-credentials-account-takeover · ATT&CK page ↗
Persistence TA0003
T1098Account Manipulation×1
Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials.
Evidence: 2026-08-19/cve-2026-18963-keycloak-reset-credentials-account-takeover · ATT&CK page ↗
Privilege Escalation TA0004
T1098Account Manipulation×1
Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials.
Evidence: 2026-08-19/cve-2026-18963-keycloak-reset-credentials-account-takeover · ATT&CK page ↗
Entries about Red Hat build of Keycloak (keycloak-services), reset-credentials flow bypass letting an unauthenticated attacker complete a password reset without the email-verification click and set new credentials, reaching full account takeover including administrators (CVSS 9.1, Red Hat as CNA; root cause improper state validation). Fixed 2026-08-18 in RHBK 26.4.15 (RHSA-2026:56520) and 26.6.6 (RHSA-2026:56523) plus the matching image and operator errata. Product-state correction (2026-08-24 audit): Red Hat records only two products under package_state, both "Not affected", the JBoss EAP Expansion Pack and Red Hat Single Sign-On 7; no Red Hat product is affected and unfixed. (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- access.redhat.com3 (75%)
- euvd.enisa.europa.eu1 (25%)
External references
All cited sources (4)
- access.redhat.comprimaryRed Hat (RHSA-2026:56523, Keycloak 26.6.6)https://access.redhat.com/errata/RHSA-2026:56523
- access.redhat.comprimaryRed Hat Product Security (structured security data)https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-18963.json
- access.redhat.comprimaryRed Hat Product Securityhttps://access.redhat.com/security/cve/CVE-2026-18963
- euvd.enisa.europa.euENISA EU Vulnerability Databasehttps://euvd.enisa.europa.eu/enisa/eu_vulnerability_database/EUVD-2026-61063