WRITEUP · PLATFORM · AUTH · CVE-2026-18963 · @YNSMROZTAS

Reset-credentials ATO class

● liveclk --:--:--CWE-640 · CVSS 9.1

Keycloak forgot-password accepted an unscoped selector, then marked the email action successful without the user-id token. The password form opened without an email click. This page is the class, not the kit.

reset // keycloakobserve
radar--:--:--
CVE-2026-18963KeycloakRed Hat SSOCWE-640

Summary

CVE-2026-18963 is an unauthenticated account-takeover class on Keycloak / Red Hat SSO. Two defects sit on the same reset-credentials path. Together they let a caller with a known username reach UPDATE_PASSWORD without the email proof the product advertised.

This is not “forgot password exists.” Forgot password existing is a feature. The finding is that the email step does not bind the session the way the design claims.

Redacted KeySniper session: ATO class, execution ids truncated, passwords stripped
Lab still rebuilt from the operator capture. Host is sso.lab.local. Users, emails, tokens and the new password painted out.

The two defects

Unscoped state plus an unverified success flag is the chain. Persistence (“the password is now something else”) is the follow-on. Report the chain, not the follow-on, as the root cause.

selector note not bound to exec id email action success() unchecked UPDATE_PASSWORD no email click fix 26.7.2 / 26.6.6 / 26.4.15. Then keep Forgot Password off until the box is patched.

Confirm signal (class)

A honest confirm is not a 200 on the login page. On an authorized lab the operator still looked for three things together:

Selector leak without the update form is not this CVE. That path is a skip.

CVE-2026-18963  Keycloak / Red Hat SSO
class            CWE-640  weak password recovery
impact           unauthenticated account takeover
auth             none
patched          26.7.2 · 26.6.6 · 26.4.15
lab              sso.lab.local · realm=master

detect is the default mode · no password body on this page

mitsec@keycloak:

Phases on the still

The capture is an authorized lab tape. Phases, not a request list:

  1. Probe — Keycloak origin, realm live, version often hidden.
  2. Reset reachable — forgot-password is enabled on that realm.
  3. Unscoped selector — the note is not tied to one execution id.
  4. Pivot — execution UUID changes. That is the leak.
  5. UPDATE_PASSWORD class — form present without the email click. This is VULN.
  6. ATO class — password actually written. That is a separate, destructive mode. Default on the public helper is detect.
Do not run a destructive mode on a host you do not own. Detect answers the question. Changing a password is an incident, not a screenshot.

Affected lines

Vulnerable below 26.7.2, and on the 26.6 / 26.4 trains below 26.6.6 and 26.4.15. Vendor fix is in those builds (Keycloak PR 51844). Confirm on the box you administer.

Fix

Repo

KeySniper stays on GitHub. This page does not mirror the script, the default new password, or a mass pipeline.

Open github.com/ynsmroztas/KeySniper →

YUNUS EMRE ÖZTAŞ · MITSEC · AUTHORIZED TESTING ONLY