Dutch NCSC Warns of Critical Keycloak Password Reset Vulnerability
A critical vulnerability in Keycloak's password reset mechanism can allow an unauthenticated attacker to take control of another user's account. CVE-2026-18963 affects the reset-credentials flow and should be treated as a priority by organizations running affected Keycloak versions.
The vulnerability allows the normal email verification step in a password reset to be bypassed. An attacker may therefore be able to set new credentials for a targeted user without access to that user's email account. Red Hat describes the result as potentially giving an attacker full control over target user accounts.
NCSC warns Keycloak users
The Dutch NCSC has also issued a warning about the vulnerability through the Digital Trust Community, recommending that organizations update Keycloak or disable password reset functionality as a temporary mitigation.
"Normally a user receives an email, but this is no longer required to reset the password. Only knowledge of the username is required to set the password."
For an identity provider such as Keycloak, the impact can extend beyond a single account: compromised credentials may provide access to several applications connected through SSO.
Check and remediate
Administrators running Keycloak in Docker Compose can quickly check the actual running version:
docker compose exec keycloak /opt/keycloak/bin/kc.sh --version
Also check the configured image, for example:
image: quay.io/keycloak/keycloak:26.6.0
Before upgrading, make a database backup. For a typical PostgreSQL Compose deployment:
docker compose exec postgres pg_dump -U keycloak -Fc keycloak > keycloak_pre_upgrade.dump
For community Keycloak, upgrade to 26.7.2 or a later release containing the fix. Keycloak 26.7.2 explicitly includes the fix for CVE-2026-18963. Red Hat Build of Keycloak uses different release numbering, with the fix provided in RHBK 26.6.6.
If upgrading immediately is impossible, disable password reset functionality on affected realms until the update can be applied. Afterwards, verify the running version and test normal authentication, SSO and legitimate password resets.
Get warned automatically with BaseFortify
BaseFortify can help identify vulnerabilities like this before they become an unpleasant surprise. Components can be added to a personal Watchlist, after which BaseFortify checks newly published CVEs for matches and sends alerts when relevant vulnerabilities are identified.
For example, a vulnerable Keycloak installation can be represented using its CPE:
cpe:2.3:a:redhat:keycloak:26.6.0:*:*:*:*:*:*:*
Users can tune the CVSS threshold, EPSS threshold and KEV flag used for alerts, allowing notifications to focus on vulnerabilities that match their own risk appetite.
BaseFortify offers both Free and Premium subscriptions. Free accounts can monitor a limited selection of components, while Premium subscriptions allow an unlimited number of components to be added to the Watchlist.
CVE-2026-18963 demonstrates the value of this approach: a newly disclosed vulnerability in a critical authentication component can require action very quickly. Knowing that a component in your environment matches the affected software is the first step towards responding in time.