ctipilot.ch
← Back to the live brief
NOTABLECVE-2026-18963updateNATOA2vulnerability

CVE-2026-18963 correction — no Red Hat product is left unfixed: the JBoss EAP Expansion Pack is recorded Not affected, and Red Hat publishes a per-realm interim mitigation

discovered 2026-08-24 08:55 UTCrun 2026-08-23T1311Z-audit2 sourcessingle-source

UPDATE · originally covered CVE-2026-18963 — Keycloak's password-reset flow can be driven to completion without the verification email being clicked, handing an unauthenticated attacker any account including administrators (CVSS 9.1) (2026-08-19)

the earlier entry read Red Hat's product-state table for CVE-2026-18963 as recording the Red Hat JBoss Enterprise Application Platform Expansion Pack as Affected with no erratum, and built a paragraph, a summary sentence and an action item on the conclusion that part of the affected estate had no patch available. That reading was wrong. Red Hat's structured security data records exactly two products under package_state, and both are "fix_state" : "Not affected" — the Expansion Pack's keycloak-services package, and Red Hat Single Sign-On 7 (Red Hat Product Security, 2026-08-18). Every other product Red Hat lists for this flaw appears under the shipped errata instead. The customer-portal page for the CVE embeds the same product-state data — "state":"Not affected", with the justifications "Component not Present" for the Expansion Pack and "Vulnerable Code not Present" for Red Hat Single Sign-On 7 (Red Hat Product Security, 2026-08-18). No Red Hat product is recorded as affected by CVE-2026-18963 and left without a fix.

The practical consequence is narrower than the original entry implied and points the other way. An operator running the Expansion Pack has nothing to remediate for this CVE, rather than an unpatchable unauthenticated account-takeover path — so a risk item raised on the strength of the earlier entry can be closed, and any compensating control applied to that product line specifically can be withdrawn. Nothing else about the flaw changes: the reset-credentials weakness in Red Hat build of Keycloak, its Critical rating, its CVSS 9.1 and the two fixed streams all stand exactly as previously reported, and an unpatched 26.4 or 26.6 deployment remains the priority.

The same record also carries an official interim step the earlier entry did not have. Red Hat states that where an immediate upgrade is not possible, "disabling the \"Forgot password\" functionality across all realms can be used as a temporary mitigation", reached in the administration console under Realm settings, Login, Forgot password, Off, and applied to every realm (Red Hat Product Security, 2026-08-18). This supersedes the reverse-proxy suggestion carried previously: turning the flow off in the product removes the vulnerable path for every client of that realm, where a proxy rule only covers traffic that traverses the proxy.

The reading error is worth naming because the shape recurs. Red Hat's package_state block enumerates the products Red Hat has assessed, not the products that are vulnerable; each row carries its own fix_state, and membership in the list says only that the product was evaluated. The same holds for the CSAF product_status groups other vendors publish and for the per-product build lists in Microsoft's Security Update Guide. Triage: a product named on a vendor advisory page is not thereby in scope — the verdict field beside it is the claim, and a product absent from the errata list may simply have been ruled out rather than left unpatched.

disabling the "Forgot password" functionality across all realms can be used as a temporary mitigation

Red Hat Product Security (structured security data) 2026-08-18

Defender actions

  • If a JBoss Enterprise Application Platform Expansion Pack deployment was scoped as exposed to CVE-2026-18963 and given a compensating control or an open no-fix risk item, close it — Red Hat records that product's keycloak-services package as Not affected, so there is no exposure to mitigate and no erratum to wait for.
  • Where Red Hat build of Keycloak 26.4.15 / 26.6.6 cannot be applied immediately, use Red Hat's own documented interim step — administration console, Realm settings, Login, Forgot password, Off — applied to every realm, in preference to blocking the reset path at the reverse proxy.

ATT&CK mapping

2 techniques mapped from the cited reporting · MITRE ATT&CK v19.2

Initial Access TA0001
T1190Exploit Public-Facing Application

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

overlap matrix · ATT&CK page ↗

Persistence TA0003
T1098Account Manipulation

Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials.

overlap matrix · ATT&CK page ↗

Privilege Escalation TA0004
T1098Account Manipulation

Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.