ended8월 24일· 1 sources

Keycloak CVE-2026-18963: Unauthenticated Password Reset Hands Over Any Account, Including Admins

Why it matters

TL;DR - what: Red Hat and the Keycloak project patched CVE-2026-18963, an improper state validation bug in the reset-credentials authentication flow that lets an unauthenticated remote attacker jump s...

1
Sources
+0
24h
Growth
4d
Active

Sources

Related Issues