GHSA-4gv3-mc9p-5wqc is a critical-severity (CVSS 9.1) CWE-640 vulnerability in org.keycloak:keycloak-services. 9 public exploit references exist, so weaponization risk is real. A fix is available for org.keycloak:keycloak-services — see the affected versions and patch details below.
Keycloak: Unauthenticated account takeover via reset-credentials flow bypass
Exploitation Status
No confirmed exploitation observed yet
- CISA assesses this as automatable — exploitation doesn’t require manual, per-target effort, which raises the odds of mass scanning and opportunistic attacks.
- A successful exploit gives an attacker total control of the affected component, not partial access.
- CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.
Exploitation and automatability from CISA’s SSVC triage for GHSA-4gv3-mc9p-5wqc.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
How urgent is this, really
GHSA-4gv3-mc9p-5wqc by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.
Where this sits among everything scored
Of 381,682 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.
Real-World Exposure
org.keycloak:keycloak-services☕org.keycloak:keycloak-services☕org.keycloak:keycloak-servicesReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects Maven packages — download data is not available via public APIs for these ecosystems.
Description
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| ☕Maven | org.keycloak:keycloak-services | ≥ 26.0.0&&< 26.4.15 | 26.4.15org.keycloak:keycloak-services:26.4.15 |
| ☕Maven | org.keycloak:keycloak-services | ≥ 26.5.0&&< 26.6.6 | 26.6.6org.keycloak:keycloak-services:26.6.6 |
| ☕Maven | org.keycloak:keycloak-services | ≥ 26.7.0&&< 26.7.2 | 26.7.2org.keycloak:keycloak-services:26.7.2 |
Research use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
ynsmroztas/KeySniper
**CVE-2026-18963** — unauthenticated Keycloak account takeover via the r
Snizi/CVE-2026-18963-Exploit
Exploit for KeyCloak CVE-2026-18963
Red-Darkin/CVE-2026-18963-keycloak
CVE-2026-18963
EQSTLab/CVE-2026-18963
Keycloak reset-credentials flow bypass
kyos-public/keycloak-cve-2026-18963-hunt
Hunt for CVE-2026-18963 exploitation traces (Keycloak unauthenticated ac
prot0tw/Keycloak_CVE-2026-18963_PoC
This repo is poc of cve-2026-18963. Please use it on legal products (lab
alt3kx/CVE-2026-18963
CVE-2026-18963 Keycloak Reset-Credentials State Bypass Detector
T0w0T/POC-CVE-2026-18963
0xlyvio/CVE-2026-18963-keycloak
CVE-2026-18963 — Keycloak reset-credentials bypass -> Account Takeover
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for org.keycloak:keycloak-services, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update org.keycloak:keycloak-services to 26.4.15 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-4gv3-mc9p-5wqc is resolved across your whole dependency graph.
Workarounds
If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.
How to detect GHSA-4gv3-mc9p-5wqc
A community-maintained Nuclei template exists for this CVE. You can scan for it directly:
nuclei -id ghsa-4gv3-mc9p-5wqc -u https://target- Template
- Keycloak < 26.7.2 - Unauthenticated Account Takeover via Reset-Credentials Bypass
- Severity
- critical
- Impact
- An unauthenticated remote attacker can force the password reset process for any user without clicking the email verification link, resulting in full account takeover.
- Remediation
- Upgrade to Keycloak 26.7.2, 26.6.6, or 26.4.15 which include fix PR #51844. Temporary mitigation: disable "Forgot Password" in all realms.
Template by ProjectDiscovery nuclei-templates (DhiyaneshDk), MIT licensed. View the full template. Scan only systems you are authorised to test.
Fixing This On Your OS
If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.
The Red Hat Product Security team has assessed the severity of this vulnerability as Critical, given that it can be exploited by an unauthenticated remote attacker without any user interaction. Successful exploitation allows an attacker to gain full access to any user account by bypassing the email verification step…
If an immediate upgrade is not possible, disabling the "Forgot password" functionality across all realms can be used as a temporary mitigation. In the RHBK administration console, navigate to: Realm settings → Login → Forgot password → Off Apply this setting to all realms. Upgrade to a fixed version as soon as possible.Source: Red Hat security advisory for GHSA-4gv3-mc9p-5wqc (CC BY 4.0)
| Product | Fixed in | Advisory |
|---|---|---|
| Red Hat build of Keycloak 26.4 | rhbk/keycloak-operator-bundle:26.4.15-1 | RHSA-2026:56519 |
| Red Hat build of Keycloak 26.4.15 | keycloak-services | RHSA-2026:56520 |
| Red Hat build of Keycloak 26.6 | rhbk/keycloak-operator-bundle:26.6.6-1 | RHSA-2026:56524 |
| Red Hat build of Keycloak 26.6.6 | keycloak-services | RHSA-2026:56523 |
Frequently Asked Questions
Is GHSA-4gv3-mc9p-5wqc in your dependencies?
Find it across Maven, including transitive dependencies.