9.1
CVE-2026-18963
- EPSS 0.39%
- Veröffentlicht 18.08.2026 17:05:07
- Zuletzt bearbeitet 08.09.2026 09:17:43
- Erkennungen
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
HerstellerSiemens
≫
Produkt
Industrial Edge Management Cloud
Default Statusunknown
Version
0
Version <
*
Status
affected
HerstellerSiemens
≫
Produkt
Industrial Edge Management Pro V1
Default Statusunknown
Version
V1.14.9
Version <
V1.15.20
Status
affected
HerstellerSiemens
≫
Produkt
Industrial Edge Management Pro V2
Default Statusunknown
Version
V2.2.0
Version <
V2.2.2
Status
affected
HerstellerSiemens
≫
Produkt
Industrial Edge Management Virtual
Default Statusunknown
Version
V2.6.0
Version <
V2.9.1
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.39% | 0.324 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| RedHat | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
CWE-640 Weak Password Recovery Mechanism for Forgotten Password
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://access.redhat.com/security/cve/CVE-2026-18963
https://bugzilla.redhat.com/show_bug.cgi?id=2511595
https://access.redhat.com/errata/RHSA-2026:56523
https://access.redhat.com/errata/RHSA-2026:56519
https://access.redhat.com/errata/RHSA-2026:56524
https://access.redhat.com/errata/RHSA-2026:56520
https://cert-portal.siemens.com/productcert/html/ssa-503852.html