CVE-CVE-2026-18963
Severity
CRITICAL
CVSS Score
9.1
Description
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials....
PoCs for CVE-CVE-2026-18963
keycloak-cve-2026-18963-hunt
General
1
kyos-public
2026-08-20
My-Exploits
General
Ruby
1
M4xSec
2026-08-31
CVE-2026-18963-Exploit
General
0
Snizi
2026-08-20
POC-CVE-2026-18963
General
Python
0
T0w0T
2026-08-24
Keycloak_CVE-2026-18963_PoC
General
Python
0
prot0tw
2026-08-25
Exploit-For-CVE-2026-18963
General
Python
0
BlackHatExploitation
2026-08-25
keycloak-CVE-2026-18963
LFI/RFI
0
gman0x00
2026-08-25