Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Critical Password Reset Flaw in Keycloak Could Let Attackers Take Over Accounts

A serious security flaw has been found in Keycloak, a tool used to manage user logins and passwords. This flaw allows attackers to reset passwords without verifying their identity, potentially taking control of user accounts. This matters because if your organisation uses Keycloak, attackers could access sensitive information or systems.

25 August 2026

Reference: CVE-2026-18963

1. What is being reported?

The report describes a weakness in the password reset process of Keycloak’s core service. Normally, users must confirm a password reset via an email link. However, this flaw lets attackers bypass that step and reset passwords directly, without needing to prove they own the account.

2. What this means in plain English

For small organisations using Keycloak to manage user access, this means an attacker could hijack user accounts, including those of staff or administrators. This could lead to data breaches, loss of control over systems, and potential disruption of business operations.

3. Could this affect a small business?

If your organisation uses Keycloak or software built on it for managing user logins, you could be at risk. If you do not use Keycloak, this vulnerability likely does not affect you. Check with your IT provider to confirm.

4. What to do now

  • Contact your IT provider or software supplier immediately to ask if your systems use Keycloak and if they are affected.
  • Apply any available security updates or patches for Keycloak as soon as they are released.
  • Review your user account management policies and monitor for unusual password reset activity.
  • Consider adding additional verification steps for password resets if possible.

5. Ask your IT provider

Does our system use Keycloak for user authentication, and if so, have we applied the latest security updates to fix the password reset vulnerability CVE-2026-18963?

6. Bottom line

If you use Keycloak, act quickly to secure your accounts against this critical password reset flaw.

Information based on NVD, CISA KEV, and reputable security news reporting.

Back to Vulnerability Briefs