CVE-2026-18963 carries a CVSS 3.1 base score of 9.1 against Red Hat Build of Keycloak, Red Hat’s supported distribution of the Keycloak open-source identity and access management platform. NVD classifies it as CWE-640 (Weak Password Recovery Mechanism for Forgotten Password). VulnCheck’s KEV feed reports the CVE as exploited, dated August 25, 2026.
That exploitation report is single-sourced. CISA has not added CVE-2026-18963 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion on September 19, 2026. VulnCheck’s catalog admits vendor and researcher exploitation reporting on broader criteria than CISA’s own listing process has accepted; no Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
NVD’s description locates the flaw in the reset-credentials flow of the keycloak-services component — described directly as “the core engine for identity and access management” in the platform. NVD states an unauthenticated attacker can force the password-reset process for any user without needing to click the required email verification link that this flow is supposed to depend on. The stated outcome is that the attacker can directly set new credentials for the targeted account, gaining full control over it.
Skipping the email-verification step is the core of what makes this severe: a password-reset flow’s entire security model rests on requiring proof that the requester controls the account’s registered email address, and NVD states that requirement can be bypassed entirely.
Evidence and confidence
- Medium confidence — the CVSS 9.1 score, the vector (
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N), the CWE-640 classification, and the full email-verification bypass mechanism all trace to NVD alone, corroborated by Red Hat’s own errata advisories cited in the same record. The exploitation report traces to VulnCheck KEV alone. - High exploitation probability — FIRST’s EPSS model scores this CVE at 0.03177, an 87.4th percentile score as of our ingestion.
No field is in conflict between our two sources. Red Hat’s own errata (RHSA-2026:56519, 56520, 56523, 56524) confirm patched builds are available, though our data does not carry a single structured fixed-version figure across Red Hat’s multiple advisory tracks.
Why this matters
Keycloak is itself an identity and access management product — the software organizations deploy specifically to centralize and strengthen authentication for other applications. A flaw that lets an unauthenticated attacker take over any account without needing to control that account’s email inbox undermines the exact guarantee Keycloak exists to provide, and the blast radius extends to every downstream application that trusts Keycloak-issued sessions as proof of identity.
Siemens’ own product security team issued an advisory referencing this CVE (cited in NVD’s reference list), indicating the flaw’s relevance extends into industrial and OT-adjacent deployments that build on Keycloak — environments where authentication compromise can have consequences well beyond a typical web application account takeover.
Frequently Asked Questions
What is CVE-2026-18963?
A CVSS 9.1 vulnerability (CWE-640) in the reset-credentials flow of Red Hat Build of Keycloak’s keycloak-services component, allowing unauthenticated attackers to force a password reset for any user without the required email verification step.
Is CVE-2026-18963 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated August 25, 2026. That report is single-sourced; CISA has not listed this CVE as of our September 19, 2026 ingestion, and we have no independent corroboration.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
Which version fixes this? Red Hat has issued multiple errata advisories (RHSA-2026:56519, 56520, 56523, 56524) with patched builds; consult Red Hat’s own CVE page for the specific advisory matching your deployment track.
Does this affect systems beyond typical web applications? Potentially. Siemens’ own product security advisory references this CVE, indicating relevance to industrial and OT-adjacent deployments that build on Keycloak for identity management.
Severity, vector, weakness classification, and the full email-verification bypass mechanism sourced from the National Vulnerability Database record for CVE-2026-18963, corroborated by Red Hat’s own CVE page and errata advisories. Siemens’ own product security advisory referencing this CVE: SSA-503852. Exploitation status and the August 25, 2026 catalog date are reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our ingestion through September 19, 2026. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.