Keycloak: Unauthenticated account takeover via reset-credentials flow bypass
Critical severity
GitHub Reviewed
Published
Aug 18, 2026
to the GitHub Advisory Database
•
Updated Aug 28, 2026
Package
Affected versions
>= 26.0.0, < 26.4.15
>= 26.5.0, < 26.6.6
>= 26.7.0, < 26.7.2
Patched versions
26.4.15
26.6.6
26.7.2
Description
Published by the National Vulnerability Database
Aug 18, 2026
Published to the GitHub Advisory Database
Aug 18, 2026
Reviewed
Aug 28, 2026
Last updated
Aug 28, 2026
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.
References