Loading...
Please wait while we get things ready for you
Please wait while we get things ready for you
Red Hat and the Keycloak project shipped version 26.7.2 on August 19 to fix CVE-2026-18963, a critical vulnerability rated 9.1 on the CVSS scale that allows unauthenticated remote attackers to hijack any account — including admin accounts — by exploiting a flawed password reset flow. The flaw, classified as a weak password recovery mechanism, lets attackers send a crafted request to the reset-credentials endpoint and skip the email verification entirely, jumping straight to...
Ask AI about this