{
 "description": "Evidence-bound MITRE ATT&CK techniques observed in ctipilot.ch entries referencing Red Hat build of Keycloak (keycloak-services) \u2014 reset-credentials flow bypass letting an unauthenticated attacker complete a password reset without the email-verification click and set new credentials, reaching full account takeover including administrators (CVSS 9.1, Red Hat as CNA; root cause improper state validation). Fixed 2026-08-18 in RHBK 26.4.15 (RHSA-2026:56520) and 26.6.6 (RHSA-2026:56523) plus the matching image and operator errata.. Score = number of published entries mapping the technique. Pinned dataset: ATT&CK v19.2.",
 "domain": "enterprise-attack",
 "gradient": {
  "colors": [
   "#ffe766",
   "#ff6666"
  ],
  "maxValue": 1,
  "minValue": 0
 },
 "hideDisabled": false,
 "layout": {
  "layout": "side",
  "showID": true,
  "showName": true
 },
 "legendItems": [],
 "metadata": [
  {
   "name": "source",
   "value": "ctipilot.ch"
  },
  {
   "name": "entity",
   "value": "CVE-2026-18963"
  },
  {
   "name": "attack_version",
   "value": "19.2"
  }
 ],
 "name": "Red Hat build of Keycloak (keycloak-services) \u2014 reset-credentials flow bypass letting an unauthenticated attacker complete a password reset without the email-verification click and set new credentials, reaching full account takeover including administrators (CVSS 9.1, Red Hat as CNA; root cause improper state validation). Fixed 2026-08-18 in RHBK 26.4.15 (RHSA-2026:56520) and 26.6.6 (RHSA-2026:56523) plus the matching image and operator errata. \u2014 ctipilot.ch coverage",
 "sorting": 3,
 "techniques": [
  {
   "comment": "entries: 2026-08-19/cve-2026-18963-keycloak-reset-credentials-account-takeover",
   "score": 1,
   "techniqueID": "T1098"
  },
  {
   "comment": "entries: 2026-08-19/cve-2026-18963-keycloak-reset-credentials-account-takeover",
   "score": 1,
   "techniqueID": "T1190"
  }
 ],
 "versions": {
  "attack": "19",
  "layer": "4.5",
  "navigator": "5.1.0"
 }
}