SécuritéNon vérifié

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset. The vulnerability, assigned the CVE identifier CVE-2026-18963, is rated 9.1 on the CVSS scoring system by Red Hat, which acts as

Contenu original affiche; la traduction localisee n'est pas encore disponible.

Ce qui s'est passé

Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset. The vulnerability, assigned the CVE identifier CVE-2026-18963, is rated 9.1 on the CVSS scoring system by Red Hat, which acts as

Pourquoi c'est important

The incident may affect operational continuity, asset safety or trust around Security. Watch for verified scope and remediation.

Entités concernées

Voir les preuves

1 articles · 1 publication d'origine · 1 independantes

  1. The Hacker NewsSource primaire · Confirme · EN · 100%
    Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Affirmations

  • Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account Signalé

Divergences

Aucune divergence importante détectée dans les preuves disponibles.

Chronologie

  1. Premier signalement

Mouvement de marché suivant l'événement

La réaction du marché n'est pas encore disponible pour cet actif et cette fenêtre.

Explication des scores

Confiance · formule confidence-2.1.0
Fiabilité des sources80
Corroboration indépendante51
Preuve primaire35
Cohérence des affirmations82
Confiance d'extraction82
Qualité de l'attribution90
Impact · formule impact-2.1.0
Ampleur de l'événement100
Pertinence marché74
Importance des entités42
Étendue du marché45
Nouveauté68
Urgence100
Classement · formule rank-1.0.0
Facteur de confiance0.748
Facteur de fraîcheur0.9977
Bonus d'urgence8
Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account | IntelCap