CVE-2026-18963 exposes vulnerable Keycloak deployments to unauthenticated account takeover through the password-reset flow.
Attackers can bypass email verification and set new credentials.
Keycloak has released patched versions for affected branches.
Enterprises should patch immediately and monitor identity and endpoint activity.
A critical Keycloak vulnerability could allow remote attackers to take over user and administrator accounts without accessing the victim’s email. The flaw turns a routine password-recovery feature into a serious identity security risk.
Tracked as CVE-2026-18963, the vulnerability carries a CVSS score of 9.1. It affects the reset-credentials authentication flow and can allow attackers to bypass the expected email-verification step. Successful exploitation could give an attacker control over accounts protected by vulnerable Keycloak deployments.
For enterprises that rely on Keycloak for authentication and SSO security, the vulnerability demands urgent attention.
What happened in the Keycloak account takeover vulnerability?
CVE-2026-18963 stems from improper state validation within Keycloak’s reset-credentials flow.
During normal password recovery, Keycloak requires the user to verify the reset request through an email action token before proceeding to password creation. The vulnerability allows an unauthenticated attacker to manipulate the authentication flow and reach the password-update stage without completing that verification step.
This weakness means an attacker could potentially set new credentials for another user and gain control of that account without possessing the original password or accessing the user’s mailbox.
Administrative accounts make the impact particularly serious. A successful Keycloak account takeover involving a privileged identity could expose applications, administrative interfaces and other services that depend on the compromised identity provider.
The vulnerability affects Keycloak releases beginning with 26.0.0 across several version branches. Patched releases include 26.4.15, 26.6.6 and 26.7.2. Upstream Keycloak 26.7 users should upgrade to 26.7.2 or later.
Organizations unable to patch immediately can temporarily disable Forgot password across affected realms. Red Hat explicitly recommends this as a temporary mitigation rather than a replacement for applying the security update.
Has CVE-2026-18963 exploitation started?
The threat picture has changed quickly since disclosure.
On August 24, The Hacker News reported that researchers had not identified exploitation or a verified public exploit. Public proof-of-concept material has since appeared online. Previdian also reports observing exploitation attempts against CVE-2026-18963 beginning on August 25.
Red Hat’s public CVE advisory currently documents the vulnerability, impact and mitigation but does not itself confirm active exploitation. Enterprises should therefore avoid treating the earlier lack of exploit activity as an indication of low risk.
Featured Resource
Cybersecurity kit
Access essential cybersecurity resources to strengthen security, reduce risk, and improve cyber resilience.
Keycloak often sits at a critical authentication boundary between users and enterprise services. Organizations may use it to manage application authentication, federated identity and single sign-on workflows.
That makes this IAM vulnerability more consequential than an isolated password-reset bug. If attackers compromise a privileged identity, they may gain legitimate credentials that allow them to interact with downstream resources as an authorized user.
Organizations should therefore review more than the Keycloak server itself. Security teams should inspect password-reset activity, privileged-account changes, authentication events and endpoint behavior associated with affected identities.
Patching remains the primary defense.
How Hexnode can strengthen defenses around Keycloak
Hexnode does not replace the Keycloak patch or remediate CVE-2026-18963 itself. Instead, Hexnode UEM and Hexnode XDR can strengthen the endpoint security controls surrounding sensitive identity infrastructure.
Hexnode UEM allows administrators to define device compliance requirements around factors such as encryption, password configuration, application compliance and device integrity. Administrators can identify endpoints that no longer meet organizational requirements and take appropriate action.
This becomes especially useful for devices used by administrators who manage identity infrastructure. Keeping privileged administration on managed, compliant endpoints reduces unnecessary exposure around high-value credentials.
Where organizations use Microsoft Entra Conditional Access, Hexnode UEM can provide device compliance data for supported Android, iOS and macOS devices so Entra Conditional Access can consider device compliance when controlling access to protected resources. This does not constitute direct Conditional Access enforcement within Keycloak.
Hexnode XDR adds threat detection and investigation capabilities for supported Windows endpoints. Security teams can monitor configured alerts for events such as process activity, network connections and system logons, while detected threats support response actions including process termination, file quarantine and endpoint isolation.
Together, these controls can help teams contain endpoint activity that follows an identity compromise while the underlying SSO security issue receives its required vendor patch.
FAQs
Which Keycloak versions fix CVE-2026-18963?
Fixed releases include Keycloak 26.4.15, 26.6.6 and 26.7.2 for their respective affected branches. Organizations should move to the appropriate patched version or a later supported release.
Can Hexnode prevent a Keycloak account takeover?
Hexnode cannot patch the Keycloak vulnerability itself. Hexnode UEM can help maintain device compliance around privileged endpoints, while Hexnode XDR can detect, investigate and respond to threats occurring on managed Windows endpoints.
Conclusion
CVE-2026-18963 shows why password recovery deserves the same scrutiny as login and authentication workflows.
Organizations running affected Keycloak versions should patch immediately or temporarily disable Forgot password until updates are deployed. Security teams should also review privileged accounts and relevant authentication activity.
Combining strong IAM controls with compliant endpoints and endpoint threat detection can further reduce the impact of a compromised identity.
Strengthen IAM Against Account Takeovers
Secure identities, enforce trusted access, and reduce account takeover risks with Hexnode Identity and UEM.
Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.