Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

redhat логотип

CVE-2026-18963

около 1 месяца назад

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2026-18963

около 1 месяца назад

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4gv3-mc9p-5wqc

около 1 месяца назад

Keycloak: Unauthenticated account takeover via reset-credentials flow bypass

CVSS3: 9.1
EPSS: Низкий
fstec логотип

BDU:2026-12649

около 1 месяца назад

Уязвимость компонента keycloak-services программного средства для управления идентификацией и доступом Keycloak, позволяющая нарушителю обойти существующие механизмы безопасности и получить несанкционированный доступ к системе

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-18963

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.

CVSS3: 9.1
3%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-18963

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.

CVSS3: 9.1
3%
Низкий
около 1 месяца назад
github логотип
GHSA-4gv3-mc9p-5wqc

Keycloak: Unauthenticated account takeover via reset-credentials flow bypass

CVSS3: 9.1
3%
Низкий
около 1 месяца назад
fstec логотип
BDU:2026-12649

Уязвимость компонента keycloak-services программного средства для управления идентификацией и доступом Keycloak, позволяющая нарушителю обойти существующие механизмы безопасности и получить несанкционированный доступ к системе

CVSS3: 9.1
3%
Низкий
около 1 месяца назад

Уязвимостей на страницу