Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
📦 Bitnami
Not in CISA KEV

CVE-2026-18963 — keycloak

CVE-2026-18963 is a CWE-640 vulnerability in keycloak. 9 public exploit references exist, so weaponization risk is real. A fix is available for keycloak — see the affected versions and patch details below.

Flaw in the reset-credentials flow of the keycloak-services component

Also known asGHSA-4gv3-mc9p-5wqc
Published
Aug 25, 2026
Updated
Aug 28, 2026
Affected
1 pkg
Patched
1 / 1
Exploits
9 known
Exploitation data as of Sep 30, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

No confirmed exploitation observed yet

  • CISA assesses this as automatable — exploitation doesn’t require manual, per-target effort, which raises the odds of mass scanning and opportunistic attacks.
  • A successful exploit gives an attacker total control of the affected component, not partial access.
  • CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.

Exploitation and automatability from CISA’s SSVC triage for CVE-2026-18963.

EPSS Exploitation Probability

via FIRST.org ↗
3.2%probability of exploitation in next 30 days
Lower Risk0.00%
Lower risk than most CVEs88th percentile — riskier than 88% of all scored CVEsHighest risk

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

Real-World Exposure

1 pkg affected
📦keycloak

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects Bitnami packages — download data is not available via public APIs for these ecosystems.

Description

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.

Affected Packages

1 total 1 fixed
EcosystemPackageVulnerable rangeFix
📦Bitnamikeycloakall versions26.7.2
Exploits & PoCs
9

Research use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for keycloak, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update keycloak to 26.7.2 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-18963 is resolved across your whole dependency graph.

  3. Workarounds

    If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.

How to detect CVE-2026-18963

A community-maintained Nuclei template exists for this CVE. You can scan for it directly:

nuclei -id cve-2026-18963 -u https://target
Template
Keycloak < 26.7.2 - Unauthenticated Account Takeover via Reset-Credentials Bypass
Severity
critical
Impact
An unauthenticated remote attacker can force the password reset process for any user without clicking the email verification link, resulting in full account takeover.
Remediation
Upgrade to Keycloak 26.7.2, 26.6.6, or 26.4.15 which include fix PR #51844. Temporary mitigation: disable "Forgot Password" in all realms.

Template by ProjectDiscovery nuclei-templates (DhiyaneshDk), MIT licensed. View the full template. Scan only systems you are authorised to test.

Fixing This On Your OS

If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.

Red HatCritical

The Red Hat Product Security team has assessed the severity of this vulnerability as Critical, given that it can be exploited by an unauthenticated remote attacker without any user interaction. Successful exploitation allows an attacker to gain full access to any user account by bypassing the email verification step…

Workaround published by Red Hat
If an immediate upgrade is not possible, disabling the "Forgot password" functionality across all realms can be used as a temporary mitigation. In the RHBK administration console, navigate to: Realm settings → Login → Forgot password → Off Apply this setting to all realms. Upgrade to a fixed version as soon as possible.
Source: Red Hat security advisory for CVE-2026-18963 (CC BY 4.0)
ProductFixed inAdvisory
Red Hat build of Keycloak 26.4rhbk/keycloak-operator-bundle:26.4.15-1RHSA-2026:56519
Red Hat build of Keycloak 26.4.15keycloak-servicesRHSA-2026:56520
Red Hat build of Keycloak 26.6rhbk/keycloak-operator-bundle:26.6.6-1RHSA-2026:56524
Red Hat build of Keycloak 26.6.6keycloak-servicesRHSA-2026:56523

Frequently Asked Questions

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.
O3 Security · Impact-Aware SCA

Is CVE-2026-18963 in your dependencies?

Find it across Bitnami, including transitive dependencies.

CVE-2026-18963: keycloak — Fixed in 26.7.2 | O3 Security