
Critical Red Hat Keycloak Flaw Lets Unauthenticated Attackers Take Over Any User Account
Red Hat has disclosed a critical vulnerability in the Red Hat Build of Keycloak that could allow unauthenticated remote attackers to take over arbitrary user accounts. Tracked as CVE-2026-18963, the flaw affects the password recovery process and carries a CVSS v3.1 score of 9.1. The vulnerability exists in the reset-credentials flow of the keycloak-services component, […]
The post Critical Red Hat Keycloak Flaw Lets Unauthenticated Attackers Take Over Any User Account appeared first on Cyber Security News.