Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
- Posted on August 24, 2026
- By The Hacker News
- 1 Views
- 1 min read
In brief
Generating AI summary…
Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
Keycloak CVE-2026-18963 could let unauthenticated attackers skip the emailed action token and reset any user's password.