Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
- ID
- 17232
- Status
- summarized
- Published
- 24 Aug 2026, 7:56 PM
- Fetched
- 24 Aug 2026, 9:53 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/08/critical-keycloak-password-reset-flaw.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 7.5
- Created
- 24 Aug 2026, 9:54 PM
- Tags
- Audience
- developerssaas_founders
What happened
A critical Keycloak vulnerability (CVE-2026-18963, CVSS 9.1) lets unauthenticated remote attackers bypass the email action token in the reset-credentials flow and reset any account's password, including admin accounts. Patches shipped August 19, 2026: upstream Keycloak 26.7.2, and Red Hat Build of Keycloak 26.4.15 and 26.6.6. No known exploitation yet.
Why it matters
If you run Keycloak for auth in your SaaS or internal apps, patch to 26.7.2 (or RHBK 26.4.15 / 26.6.6) immediately — the flaw requires no user interaction and yields full account takeover. If you cannot patch right away, review whether your reset-credentials flow is internet-exposed and consider temporarily restricting it.
Discussion angle
How many Malaysian startups self-host Keycloak vs. use managed auth (Auth0, Cognito) — and does this kind of critical IAM flaw change the calculus toward managed services?