
[CIVN-2026-0442] Authentication Bypass Vulnerability in Keycloak
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Authentication Bypass Vulnerability in Keycloak
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
Keycloak versions prior to 26.7.2.
Red Hat build of Keycloak (RHBK)
Versions 26.4 prior to 26.4.15
Versions 26.6 prior to 26.6.6
Overview
A critical vulnerability has been reported in Keycloak, which could allow an unauthenticated attacker to bypass the password reset mechanism and take over arbitrary user accounts, including administrative accounts.
Target Audience:
Organizations and administrators using affected versions of Keycloak and Red Hat build of Keycloak (RHBK).
Risk Assessment:
Critical risk of unauthenticated account takeover, unauthorized access, and compromise of administrative accounts.
Impact Assessment:
Potential for authentication bypass, unauthorized password reset, account takeover, and privilege escalation through compromised administrative accounts.
Description
Keycloak is an open-source identity and access management platform used to provide authentication and authorization services for applications and services.
A vulnerability has been reported in Keycloak due to improper state validation within the reset-credentials authentication flow. An attacker may send a specially crafted request to the reset-credentials endpoint, causing the authentication session to transition directly to the password update phase without requiring the action token normally delivered through email.
Successful exploitation could allow an unauthenticated attacker to bypass the password reset mechanism and take over user accounts, including administrative accounts.
Solution
Users are advised to upgrade to the latest available version:
Upstream Keycloak: Upgrade to 26.7.2 or later.
Red Hat build of Keycloak 26.4: Upgrade to 26.4.15 or later.
Red Hat build of Keycloak 26.6: Upgrade to 26.6.6 or later.
Note: As a temporary mitigation, organizations that cannot immediately apply the security updates should disable the Forgot password functionality across all Keycloak realms until the affected systems can be upgraded.
Vendor Information
https://www.keycloak.org/
References
https://www.keycloak.org/2026/08/keycloak-2672-released
CVE Name
CVE-2026-18963
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqe13sACgkQ3jCgcSdc
ys/pcw//bsj48E2Hlr0Ov3rRJG/3mwQyZb/l2DL1tfZQbnclpTV9BhBxUvc+KAqV
cwf8vEeTMpyr+eYsd+4m20Cf8ThKnxdgXnPhB4+JW4MfbWa8Yn06tX+2vsAEGvuR
qMULxwQEmfgUxbqdlQxNNyPMGr1kB1FM40VYs8sQkB7zwgHwTxdGMaqPeJItuUil
mW4ByU/P4ZTpQ3XWQC4XP+10awh2myE7Cm9uvFE0I19q7Aq1dGevvpx6T0D+iL7/
2ldW8pmfcXJ/YvxsdbsVfYpfO67yt8FJRVuJv5n4qC04DPZe7sjsbRO7tcu4FA0U
dj28oKr+C0CA5mMG7+IKkJskY9c/Rq75pZ8qdm99YWkzvuNPyK9grXNPF8R2NdKw
DN151IsyZzW+GbM9FQDTMxdzhJ8FmzvvSESSNX99UkTcPKu0fcvgkWq1yOYkY4B6
LXZB0cLElsJIw5IIE1+FvXhfTHyTcmQbT/XZrPJWUkM0h+Vn7/OsgoAU2ZxoNiH4
4YvPmcZ+77wQBi5oZhm1gV5fms7ntuDmhvGgCsSBZp8mhf2uu+Am41Omql+fsIS1
b9aCPlG9WpSQ/z1sUYKUBqHt9rqHdbph4hVl1tnJjD7XrI0W8+lHTbNv8gJdo8WZ
oIYGr3JUqjHXC9vS3DvCYUqw2FDL1CJWIlJ0hSZemQOJhEANo3o=
=soDH
—–END PGP SIGNATURE—–


