On August 24-25, 2026, Red Hat and the Keycloak project released fixes for CVE-2026-18963, a critical password-reset vulnerability (CVSS 9.1) in the open-source identity server allowing unauthenticated attackers to force password resets without email access. A sixth post about an unrelated Metabase SQL injection was captured.
11 reportsother
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
Red Hat and the Keycloak project released fixes for CVE-2026-18963, a critical password-reset flaw in the open-source identity and access management server that could let an unauthenticated remote attacker take over any account, including administrative accounts, by forcing a password reset [thehackernews.com#1]. Red Hat rated the vulnerability 9.1 on the CVSS scale and said it stemmed from improp
🤖 CVE-2026-18963 (CVSS 9.1): critical unauthenticated account takeover in Keycloak. Improper state validation in the reset-credentials flow lets an attacker force a password reset without the email action token, taking over any account, including admins. Fixed in 26.7.2; RHBK 26.4.15/26.6.6. No public exploit reported yet. 🔗 https:// thehackernews.com/2026/08/crit ical-keycloak-password-reset-fl
Critical Keycloak Password Reset Flaw Allows Unauthenticated Account Takeover Red Hat and Keycloak patched a critical vulnerability (CVE-2026-18963) that allows unauthenticated attackers to bypass email verification and take over any account via the password reset flow. The update also addresses over 20 other security flaws, including account-linking bypasses and administrative permission leaks. *
Critical Keycloak flaw CVE-2026-18963 lets attackers take over any account in seconds, bypassing MFA and email verification. CVSS 9.1. Patch to 26.7.2, 26.4.15, or 26.6.6, or https:// deafnews.it/en/article/cve-202 6-18963-keycloak-account-takeover-in-seconds-bypassing-mfa
🏆 New Achievement! Exhibit A: Your Password Reset Button! Counsel will direct the court's attention to CVE-2026-18963, rated a damning 9.1 out of 10, wherein Keycloak's reset-credentials authentication flow failed to properly validate state — legally speaking, an open invitation any unauthenticated remote party was fully entitled to accept. No user interaction required. The attacker needed nothin
⚠️ CRITICAL: Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account Critical flaw in Keycloak (CVE-2026-18963, CVSS 9.1) allows unauthenticated attackers to reset any user password and take over accounts due to improper state validation in the password recovery flow. Any organization running Keycloak without patches is immediately at risk of account takeove
Note the recently disclosed CVE-2026-18963 for # Keycloak OIDC: https:// thehackernews.com/2026/08/crit ical-keycloak-password-reset-flaw.html . It allows unauthorized users to take over any account on your server. On the # Slackware # Forgejo instance https:// forge.slackware.nl/ I have upgraded Keycloak to 26.7.2 to address this vulnerability.
Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account reconbee.com/critical-key... #keycloak #keycloakpassword #attackers #cybersecurity #cyberattack A serious security vulnerability in the open-source identity and access management server has been fixed by Red Hat and the Keycloak project. This vulnerability might enable an unauthenticated remote ...
Keycloak Password Reset Bypass (CVE-2026-18963): Any Account, No Login Required If your organization uses Keycloak to manage employee or customer logins, this is worth reading regardless of how technical your role is. A newly disclosed flaw means that, in some configurations, anyone on the internet could take over any account on your system, including administrator accounts, si... https:// insomni
🚨 CRITICAL: CVE-2026-72898 is an actively exploited Metabase SQL injection. A CVSS 10.0, unauthenticated Metabase vulnerability can let remote attackers exploit the password-reset flow, gain administrator access, and potentially expose credentials and data from connected databases. No credentials. No user interaction. I broke down the CVE-2026-72898 exploit chain, affected Metabase versions, atta