[CIVN-2026-0442] Authentication Bypass Vulnerability in Keycloak

By Published On: September 7, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Authentication Bypass Vulnerability in Keycloak


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


Keycloak versions prior to 26.7.2.

Red Hat build of Keycloak (RHBK) 

Versions 26.4 prior to 26.4.15

Versions 26.6 prior to 26.6.6

Overview


A critical vulnerability has been reported in Keycloak, which could allow an unauthenticated attacker to bypass the password reset mechanism and take over arbitrary user accounts, including administrative accounts.


Target Audience:

Organizations and administrators using affected versions of Keycloak and Red Hat build of Keycloak (RHBK).


Risk Assessment:

Critical risk of unauthenticated account takeover, unauthorized access, and compromise of administrative accounts.


Impact Assessment:

Potential for authentication bypass, unauthorized password reset, account takeover, and privilege escalation through compromised administrative accounts.


Description


Keycloak is an open-source identity and access management platform used to provide authentication and authorization services for applications and services.


A vulnerability has been reported in Keycloak due to improper state validation within the reset-credentials authentication flow. An attacker may send a specially crafted request to the reset-credentials endpoint, causing the authentication session to transition directly to the password update phase without requiring the action token normally delivered through email.


Successful exploitation could allow an unauthenticated attacker to bypass the password reset mechanism and take over user accounts, including administrative accounts.


Solution


Users are advised to upgrade to the latest available version:

Upstream Keycloak: Upgrade to 26.7.2 or later.

Red Hat build of Keycloak 26.4: Upgrade to 26.4.15 or later.

Red Hat build of Keycloak 26.6: Upgrade to 26.6.6 or later.

Note: As a temporary mitigation, organizations that cannot immediately apply the security updates should disable the Forgot password functionality across all Keycloak realms until the affected systems can be upgraded.


Vendor Information


 

https://www.keycloak.org/


References


 

https://www.keycloak.org/2026/08/keycloak-2672-released


CVE Name

CVE-2026-18963




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqe13sACgkQ3jCgcSdc

ys/pcw//bsj48E2Hlr0Ov3rRJG/3mwQyZb/l2DL1tfZQbnclpTV9BhBxUvc+KAqV

cwf8vEeTMpyr+eYsd+4m20Cf8ThKnxdgXnPhB4+JW4MfbWa8Yn06tX+2vsAEGvuR

qMULxwQEmfgUxbqdlQxNNyPMGr1kB1FM40VYs8sQkB7zwgHwTxdGMaqPeJItuUil

mW4ByU/P4ZTpQ3XWQC4XP+10awh2myE7Cm9uvFE0I19q7Aq1dGevvpx6T0D+iL7/

2ldW8pmfcXJ/YvxsdbsVfYpfO67yt8FJRVuJv5n4qC04DPZe7sjsbRO7tcu4FA0U

dj28oKr+C0CA5mMG7+IKkJskY9c/Rq75pZ8qdm99YWkzvuNPyK9grXNPF8R2NdKw

DN151IsyZzW+GbM9FQDTMxdzhJ8FmzvvSESSNX99UkTcPKu0fcvgkWq1yOYkY4B6

LXZB0cLElsJIw5IIE1+FvXhfTHyTcmQbT/XZrPJWUkM0h+Vn7/OsgoAU2ZxoNiH4

4YvPmcZ+77wQBi5oZhm1gV5fms7ntuDmhvGgCsSBZp8mhf2uu+Am41Omql+fsIS1

b9aCPlG9WpSQ/z1sUYKUBqHt9rqHdbph4hVl1tnJjD7XrI0W8+lHTbNv8gJdo8WZ

oIYGr3JUqjHXC9vS3DvCYUqw2FDL1CJWIlJ0hSZemQOJhEANo3o=

=soDH

—–END PGP SIGNATURE—–

Share this article