info@news-matic.com

details

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Keycloak CVE-2026-18963 could let unauthenticated attackers skip the emailed action token and reset any user's password. Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a passwor... [4111 chars]

ADVERTISEMENT

Cookie Consent + Tracking