Affected Systems
Keycloak identity and access management server: upstream versions prior to 26.7.2; Red Hat build of Keycloak (RHBK) 26.4 prior to 26.4.15 and 26.6 prior to 26.6.6. All realms with "Forgot password" feature enabled are vulnerable.
Exploitation Status
No evidence of active exploitation as of August 24, 2026. No verified public exploit available. Proof-of-concept details published in Red Hat bug report describe the attack method (crafted request to reset-credentials endpoint bypasses email token requirement).
Business Impact
Complete account takeover of any user, including administrative accounts, without authentication or user interaction. Attackers can reset passwords by exploiting improper state validation in the reset-credentials flow. Organizations using Keycloak as SSO/IAM gateway face cascading compromise of all downstream applications and services. CVSS 9.1 (Critical).
Urgency
🔴 Immediate
Recommended Actions
- Update upstream Keycloak to version 26.7.2 immediately (released August 19, 2026).
- Apply Red Hat build of Keycloak updates: 26.4.15-1 (operator bundle), 26.4-23 (container images) for RHBK 26.4 stream; 26.6.6-1 (operator bundle), 26.6-12 (containers) for RHBK 26.6 stream.
- If immediate patching is not possible, disable 'Forgot password' functionality in all Keycloak realms via Realm settings > Login > Forgot password in the administration console.
- Review authentication logs for anomalous password reset activity or direct requests to reset-credentials endpoints that bypass email token validation.
- Audit administrative account access and force password resets for privileged accounts after patching to ensure no prior compromise.
