
Critical Red Hat Keycloak Password Reset Flaw Enables Unauthenticated Account Takeover
Red Hat has disclosed a critical vulnerability in the Red Hat Build of Keycloak that allows an unauthenticated remote attacker to bypass a key safeguard in the password reset process and seize control of arbitrary user accounts. Tracked as CVE-2026-18963, the flaw affects the keycloak-services component, the core identity and access management engine behind the […]
The post Critical Red Hat Keycloak Password Reset Flaw Enables Unauthenticated Account Takeover appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.