EXECUTIVE SUMMARY:
Multiple vulnerabilities have been identified in Keycloak, including flaws that could allow attackers to compromise user accounts and bypass security controls. The vulnerabilities affect password recovery and account-linking mechanisms, where improper state validation in the reset-credentials authentication flow could enable unauthenticated remote attackers to bypass email-based verification and take over user accounts, while predictable account-linking hashes could allow account takeover through malicious OpenID Connect clients. Successful exploitation of these vulnerabilities may result in unauthorized access to user accounts, including privileged accounts, and compromise applications protected by Keycloak.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Multiple vulnerabilities have been identified in Keycloak, including flaws that could allow attackers to compromise user accounts and bypass security controls. The vulnerabilities affect password recovery and account-linking mechanisms, where improper state validation in the reset-credentials authentication flow could enable unauthenticated remote attackers to bypass email-based verification and take over user accounts, while predictable account-linking hashes could allow account takeover through malicious OpenID Connect clients. Successful exploitation of these vulnerabilities may result in unauthorized access to user accounts, including privileged accounts, and compromise applications protected by Keycloak.[emaillocker id="1283"]
CVE-2026-18963 (CVSS 9.1 — Critical): An unauthenticated remote attacker can exploit the flaw without any user interaction by sending a specially crafted request to the reset-credentials endpoint, resulting in a complete account takeover of any user, including administrative accounts.
CVE-2026-15571 (CVSS 7.3 — High): A Keycloak account-linking vulnerability allows a malicious OIDC client to predict the linking hash, forge account-linking requests, and achieve full account takeover by linking an attacker-controlled identity to a victim's account.
RECOMMENDATIONS:
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2026/08/critical-keycloak-password-reset-flaw.html