
Red Hat Keycloak Password Reset Flaw Enables Unauthenticated Account Takeover
Red Hat has disclosed a critical vulnerability in its Build of the Keycloak identity and access management platform that could allow remote, unauthenticated attackers to take over arbitrary user accounts. Tracked as CVE-2026-18963, the flaw stems from a bypass in the password-reset workflow and carries a CVSS v3.1 score of 9.1 out of 10. The […]
The post Red Hat Keycloak Password Reset Flaw Enables Unauthenticated Account Takeover appeared first on Cyber Security News.