What is CVE-2026-18963?
CVE-2026-18963 is a flaw in the 'keycloak-services' component of Red Hat Build of Keycloak that allows an unauthenticated attacker to force the password reset process for any user without requiring the expected user click. This issue originates in the reset-credentials flow. Affected systems should be patched immediately.
Azərbaycanca: CVE-2026-18963 Red Hat Build of Keycloak-in 'keycloak-services' komponentində autentifikasiya olunmamış hücumçuya hər hansı bir istifadəçinin şifrəsini sıfırlama prosesini məcbur etməyə imkan verən boşluqdur. Bu, 'reset-credentials' axınındakı qüsurdan qaynaqlanır. Təsirə məruz qalan sistemlərdə dərhal yamaq tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-287; shared vendor: Red Hat
FAQ2
Which component in Red Hat Build of Keycloak does CVE-2026-18963 affect?
This flaw affects the 'keycloak-services' component.
What is the primary cause of CVE-2026-18963?
The vulnerability originates from a flaw in the reset-credentials flow.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.