Home / Aug 25, 2026 / Story
0
#2 The Hacker News general August 24, 2026 at 11:56 UTC

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

By [email protected] (The Hacker News)

AI Summary

A critical vulnerability (CVE-2026-18963, CVSS 9.1) in Keycloak, the widely-deployed open-source identity and access management server maintained by Red Hat, allows unauthenticated remote attackers to take over any user account by forcing a password reset. Red Hat and the Keycloak project have released patches, making immediate upgrade essential for any organization using Keycloak for SSO or OAuth flows.

Relevance score: 85.0/100

# More from August 25