9.1

CVE-2026-18963

Medienbericht

Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
HerstellerSiemens
≫
Produkt Industrial Edge Management Cloud
Default Statusunknown
Version 0
Version < *
Status affected
HerstellerSiemens
≫
Produkt Industrial Edge Management Pro V1
Default Statusunknown
Version V1.14.9
Version < V1.15.20
Status affected
HerstellerSiemens
≫
Produkt Industrial Edge Management Pro V2
Default Statusunknown
Version V2.2.0
Version < V2.2.2
Status affected
HerstellerSiemens
≫
Produkt Industrial Edge Management Virtual
Default Statusunknown
Version V2.6.0
Version < V2.9.1
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.324
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE-640 Weak Password Recovery Mechanism for Forgotten Password

The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
25.08.2026 11:00
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
24.08.2026 18:15
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
24.08.2026 14:29
https://access.redhat.com/security/cve/CVE-2026-18963
https://bugzilla.redhat.com/show_bug.cgi?id=2511595
https://access.redhat.com/errata/RHSA-2026:56523
https://access.redhat.com/errata/RHSA-2026:56519
https://access.redhat.com/errata/RHSA-2026:56524
https://access.redhat.com/errata/RHSA-2026:56520
https://cert-portal.siemens.com/productcert/html/ssa-503852.html