Critical Keycloak Flaw Lets Hackers Hijack Accounts Without a Password
Red Hat and the Keycloak project have released security updates to fix a critical vulnerability that could allow an unauthenticated attacker to take over any user account by forcing a password reset. Tracked as CVE-2026-18963, the flaw has been rated 9.1 out of 10 on the severity scale, marking it as a top-priority issue for any organisation using the software.
Keycloak is a widely used open-source tool that businesses rely on to manage user logins, single sign-on, and access permissions across their applications. Because it sits at the centre of how employees and customers authenticate, a flaw allowing account takeover without prior login credentials poses a serious risk of unauthorised access to sensitive systems and data.
Organisations using Keycloak, whether directly or through vendor products built on it, should apply the available patches as soon as possible. Given the severity rating and the fact that no authentication is required to exploit the flaw, this vulnerability is likely to attract attention from opportunistic attackers scanning for unpatched systems.