/Vulnerability Library

Keycloak < 26.7.2 - Unauthenticated Account Takeover via Reset-Credentials Bypass

CVE-2026-18963
Verified

Description

Keycloak versions prior to 26.7.2, 26.6.6, and 26.4.15 contain a flaw in the reset-credentials flow that allows an unauthenticated attacker to bypass email verification and take over any user account. Two bugs are chained: (1) the tryAnotherWay handler stores a generic "true" selector note not scoped to the execution ID, and (2) ResetCredentialEmail.action() calls context.success() without verifying ACTION_TOKEN_USER_ID.

Severity

Critical

CVSS Score

9.1

Exploit Probability

3%

Affected Product

keycloak

Published Date

August 24, 2026

Template Author

dhiyaneshdk

CVE-2026-18963.yaml
9.1Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVE ID:
cve-2026-18963
CWE ID:
cwe-640

References

https://nvd.nist.gov/vuln/detail/CVE-2026-18963https://github.com/keycloak/keycloak/pull/51844https://github.com/keycloak/keycloak/issues/51833https://github.com/T0w0T/POC-CVE-2026-18963https://access.redhat.com/security/cve/cve-2026-18963

Remediation Steps

Upgrade to Keycloak 26.7.2, 26.6.6, or 26.4.15 which include fix PR #51844. Temporary mitigation: disable "Forgot Password" in all realms.