2026-10-11 18:00 UTC

identity-security

band: coolmomentum: stable score: 0.003
temperature history

Episodes (2)

Independent reproduction and vendor response will determine whether CVE-2026-18963 permits practical Keycloak account takeover through a reset-credentials bypass and requires urgent remediation.
expiredknownscott: low
Maintainer triage and independent reproduction will determine whether Keycloak’s reset-credentials flow permits unauthenticated account takeover in supported configurations and requires a security patch.
resolvedknownscott: low

Trajectory notes