ended8월 24일· 1 sources
Keycloak CVE-2026-18963: Unauthenticated Password Reset Hands Over Any Account, Including Admins
Why it matters
TL;DR - what: Red Hat and the Keycloak project patched CVE-2026-18963, an improper state validation bug in the reset-credentials authentication flow that lets an unauthenticated remote attacker jump s...
1
Sources
+0
24h
—
Growth
4d
Active