Identity-Provider
Keycloak's Reset-Credentials Flow Lets Unauthenticated Attackers Take Over Any Account (CVE-2026-18963)
CVE-2026-18963 lets an unauthenticated attacker skip email verification in Keycloak's password-reset flow and set new credentials on any account. Patch to 26.7.2 (or 26.4.15/26.6.6 for Red Hat builds) now.