SeguridadNo verificado

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset. The vulnerability, assigned the CVE identifier CVE-2026-18963, is rated 9.1 on the CVSS scoring system by Red Hat, which acts as

Se muestra el contenido original; la traduccion localizada aun no esta disponible.

Qué ocurrió

Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset. The vulnerability, assigned the CVE identifier CVE-2026-18963, is rated 9.1 on the CVSS scoring system by Red Hat, which acts as

Por que importa

The incident may affect operational continuity, asset safety or trust around Security. Watch for verified scope and remediation.

Entidades afectadas

Ver evidencia

1 articulos · 1 informe original · 1 independientes

  1. The Hacker NewsFuente primaria · Respalda · EN · 100%
    Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Afirmaciones

  • Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account Reportado

Conflictos

No se detectaron conflictos importantes en la evidencia disponible.

Cronología

  1. Primera publicación

Movimiento del mercado posterior al evento

La reacción del mercado aún no está disponible para este activo y periodo.

Explicación de puntuaciones

Confianza · fórmula confidence-2.1.0
Fiabilidad de fuentes80
Corroboración independiente51
Evidencia primaria35
Coherencia de afirmaciones82
Confianza de extracción82
Calidad de atribución90
Impacto · fórmula impact-2.1.0
Magnitud del evento100
Relevancia de mercado74
Importancia de entidades42
Alcance del mercado45
Novedad68
Urgencia100
Clasificación · fórmula rank-1.0.0
Factor de confianza0.748
Factor de actualidad0.9977
Bono de urgencia8
Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account | IntelCap