Post cover image

August 30, 2026

CVE-2026–18963: Breaking Down Keycloak’s reset-credentials Auth Bypass

TL;DR: an unauthenticated attacker who only knew a victim’s username could reach the “set a new password” step of Keycloak’s…

By Guidancewhite

4 min read