National Cyber Warfare Foundation (NCWF)

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account


0 user ratings
2026-08-24 12:09:03
milo
Blue Team (CND)
Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset.

The vulnerability, assigned the CVE identifier CVE-2026-18963, is rated 9.1 on the CVSS scoring system by Red Hat, which acts as



Source: TheHackerNews
Source Link: https://thehackernews.com/2026/08/critical-keycloak-password-reset-flaw.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.