NCSC-2026-0326 [1.00] [M/H] Vulnerabilities patched in Keycloak
Red Hat has patched multiple vulnerabilities in Keycloak. The vulnerability with CVE-2026-18963 can enable an unauthenticated external attacker to take over any user account by forcing a password reset. This vulnerability allows bypassing the email verification process during password reset and modifying user passwords. Additionally, vulnerabilities exist in Fine-Grained Admin Permissions (FGAP) v2, allowing certain administrators with limited permissions to view metadata of hidden groups and expose details of unauthorized parent groups. Furthermore, authenticated attackers can bypass CSRF protection via a legacy client-initiated account-linking endpoint and take over accounts. Delegated administrators with only read permissions can also read client secrets due to an error in secret rotation. For OpenTelemetry Java, a vulnerability existed where the lack of limits on baggage headers led to unbounded memory and CPU usage, which can cause Denial-of-Service. In Jackson libraries, a bypass of the @JsonIgnore annotation in Java Records was identified, allowing unwanted assignment to constructor parameters. There are also bypasses of @JsonIgnoreProperties, missing view guards on @JsonUnwrapped, and unauthorized write actions on fields with @JsonView. Oracle Database Server's Fleet Patching and Provisioning component is also affected by a vulnerability that can cause unauthorized data access or Denial-of-Service.
CSIRTS triage
- What
- Multiple vulnerabilities allow unauthenticated attackers to take over user accounts via password reset bypass, authenticated attackers to bypass CSRF protection and take over accounts, and administrators with limited permissions to view hidden group metadata and read client secrets.
- Who is affected
- All Keycloak deployments and users are affected; attackers can take over any user account.
- Urgency
- Critical; account takeover vulnerabilities are actively exploitable with no user interaction required.
- Action
- Apply Red Hat's Keycloak security patches immediately to all instances.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Keycloak
Get an email when a new Keycloak advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0326
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2026-189632.8% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 85% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-18963 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Keycloak
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-79652: A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-serv…nvd · 2026-08-25
- high[NEW] [high] Keycloak: Multiple vulnerabilitiescert-bund · 2026-08-25
- unknownMultiple vulnerabilities in Keycloak (August 25, 2026)cert-fr-avis · 2026-08-25
- mediumCVE-2025-68833: HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which…nvd · 2026-08-24
- medium[UPDATE] [medium] Keycloak: Multiple vulnerabilitiescert-bund · 2026-08-19
- medium[NEW] [UNPATCHED] [medium] Keycloak: Multiple vulnerabilitiescert-bund · 2026-08-19
More from NCSC-NL Advisories
- unknownNCSC-2026-0303 [1.01] [M/H] Vulnerabilities patched in GitLab by GitLab Inc.2026-08-25
- unknownNCSC-2026-0325 [1.00] [M/H] Vulnerabilities patched in Atlassian products2026-08-24
- unknownNCSC-2026-0324 [1.00] [M/H] Vulnerability fixed in Zimbra Collaboration Suite2026-08-23
- unknownNCSC-2026-0323 [1.00] [M/H] Vulnerabilities fixed in Cisco Secure Workload2026-08-21
- unknownNCSC-2026-0322 [1.00] [M/H] Vulnerabilities fixed in Splunk Enterprise by Splunk2026-08-21