We had several requests regarding a Keycloak Security issue with a high impact (CVSS >9), so I’d like to give a short update:
Keycloak released version 26.7.2 yesterday, which includes a fix for security issue CVE-2026-18963 which allows attackers to set new passwords for any accounts due to an issue in the “forgotten password” implementation of Keycloak. The affected feature allows End User who forgot their password to receive an e-mail with a link to set a new password.
Nubus is not affected by this issue, as this feature is not activated in our Keycloak deployments (and must not be activated, as it is incompatible to Nubus). We link to our own Self Service for this use case.
But we will update to Keycloak 26.7.2 anyway, as it fixes other issues.
Technical details can be found in the Keycloak Release Notes Keycloak 26.7.2 released - Keycloak including a link to the github issue for this CVE CVE-2026-18963 Unauthenticated account takeover via reset-credentials flow bypass · Issue #51833 · keycloak/keycloak · GitHub
You can check your own Keycloak deployment by looking into the Realm “Login” Settings. The “Forgot Password” Option must be deactivated:
