A critical vulnerability (CVE-2026-18963) in the keycloak-services component allows unauthenticated attackers to hijack user accounts by bypassing password reset verification requirements.
PoC
Red Hat Build of Keycloak +1
authentication-bypass
identity-management
cve-2026-18963
1t
1c
updated