Keycloak < 26.7.2 - Unauthenticated Account Takeover via Reset-Credentials Bypass
CVE-2026-18963
Verified
Description
Keycloak versions prior to 26.7.2, 26.6.6, and 26.4.15 contain a flaw in the reset-credentials flow that allows an unauthenticated attacker to bypass email verification and take over any user account. Two bugs are chained: (1) the tryAnotherWay handler stores a generic "true" selector note not scoped to the execution ID, and (2) ResetCredentialEmail.action() calls context.success() without verifying ACTION_TOKEN_USER_ID.
Severity
Critical
CVSS Score
9.1
Exploit Probability
3%
Affected Product
keycloak
Published Date
August 24, 2026
Template Author
dhiyaneshdk
CVE-2026-18963.yaml
9.1Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVE ID:
cve-2026-18963
CWE ID:
cwe-640
Remediation Steps
Upgrade to Keycloak 26.7.2, 26.6.6, or 26.4.15 which include fix PR #51844. Temporary mitigation: disable "Forgot Password" in all realms.