2026-10-11 18:04 UTC

Independent reproduction and vendor response will determine whether CVE-2026-18963 permits practical Keycloak account takeover through a reset-credentials bypass and requires urgent remediation.

state: expiredheat: lowuncertainty: mediumknownscott: lowidentity-security keycloak authentication-bypassKeycloak

What is this?

CVE-2026-18963 is described by NVD and Red Hat as a flaw in the reset-credentials flow of the Keycloak services component used in Red Hat Build of Keycloak. It allegedly lets an unauthenticated attacker bypass the required email-verification step, set new credentials for a target user, and take over the account; a Belgian government advisory rates it CVSS 9.1 and urges patching. The supplied snippets confirm a vendor-described vulnerability but do not provide an independent technical reproduction, clearly identify affected versions, or substantiate claims of active exploitation.

Why it matters to Scott

The radar already tracks this exact development in “Maintainer triage and independent reproduction will determine whether Keycloak’s…” (radar:keycloak-reset-credentials-takeover). Its conditional treatment aligns with Scott’s Security Reviewer Method and bounded security-context escalation, but the hits show no active Keycloak work or new evidence that would change what he builds or argues.
ip:source.security-reviewer-method-ebookip:concept.bounded-security-context-escalationradar:keycloak-reset-credentials-takeover
queries asked of Scott's wikis
  • password-reset flow security boundaries
  • Keycloak deployments and authentication architecture
  • identity-provider account takeover blast radius
  • email verification and recovery-token design
  • urgent patching criteria for IAM vulnerabilities
  • authentication bypass testing in security harnesses

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (1) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hn ⭐CVE-2026-18963 – Keycloak Reset-Credentials Bypass → Account Takeovermqus30

Interpretation history

Decision trace