TL;DR what: Red Hat and the Keycloak project patched CVE-2026-18963, an improper state validation bug in the reset-credentials authentication flow that lets an unauthenticated remote attacker jump straight to the password update phase without the emailed action token. impact: Successful exploita...
Source: [Dev.to](https://dev.to/etairos/keycloak-cve-2026-18963-unauthenticated-password-reset-hands-over-any-account-including-admins-2g89)