Unauthenticated account takeover via password-reset bypass in Red Hat Build of Keycloak and Siemens Industrial Edge Management

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2026-18963?

CVE-2026-18963 is a vulnerability classified as Weak Password Recovery Mechanism for Forgotten Password, affecting Red Hat build of Keycloak 26.4 and Red Hat build of Keycloak 26.6. This vulnerability is rated Critical, with a CVSS score of 9.1. Current sources do not report this vulnerability as exploited.

Overview

Original source data

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.

Affected products and scope

  • Red Hat Build of Keycloak 26.4: The normalized record marks rhbk/keycloak-operator-bundle, rhbk/keycloak-rhel9, and rhbk/keycloak-rhel9-operator as affected. Red Hat identifies standalone 26.4.15 as fixed; corresponding image artifacts are listed in the VEX data with the 26.4.15-1 and 26.4-23 tags, depending on the package or Operator form.
  • Red Hat Build of Keycloak 26.6: The rhbk/keycloak-operator-bundle, rhbk/keycloak-rhel9, and rhbk/keycloak-rhel9-operator packages are marked affected. Red Hat identifies standalone 26.6.6 as fixed; corresponding image artifacts are listed with the 26.6.6-1 and 26.6-12 tags.
  • Red Hat product status: Red Hat VEX states that keycloak-services is not present in Red Hat JBoss Enterprise Application Platform Expansion Pack and that vulnerable code is not present in Red Hat Single Sign-On 7. This status applies to those products and does not establish that every third-party product using Keycloak is unaffected.
  • Siemens Industrial Edge Management Cloud: Siemens identifies all versions as affected. The service was mitigated with firewall rules and fixed through a service-side update, with no customer action required according to the advisory.
  • Siemens Industrial Edge Management Pro V1: Versions >= V1.14.9 < V1.15.20 are affected. The specified fix is V1.15.20 or a later version.
  • Siemens Industrial Edge Management Pro V2: Versions >= V2.2.0 < V2.2.2 are affected. The specified fix is V2.2.2 or a later version.
  • Siemens Industrial Edge Management Virtual: Versions >= V2.6.0 < V2.9.1 are affected. The specified fix is V2.9.1 or a later version.

Technical details

The affected component is keycloak-services in the reset-credentials authentication flow of Red Hat Build of Keycloak. Red Hat identifies improper state validation within that authentication flow as the root cause. An unauthenticated remote request can move the authentication session directly to the password-update phase without the action token normally delivered through email, allowing the attacker to set new credentials for the target account. This is classified as CWE-640, Weak Password Recovery Mechanism for Forgotten Password. The exact request fields, complete request sequence, and scope for other products embedding Keycloak are not established by the available evidence.

Exploitability

  • The vulnerable flow is reachable over the network and does not require prior attacker authentication.
  • The victim does not need to click the email verification link or perform any other user interaction.
  • The supplied record does not identify a public exploit, and the inspected Red Hat sources do not name a campaign, victim, or specific exploitation activity. Actual exploitation status therefore remains unknown.

Technical impact

Successful exploitation allows an attacker to set a new password or credential for a target account and assume that account's identity. Administrative accounts are explicitly within the described scope, so the consequence can extend beyond one user depending on assigned privileges. For Red Hat Build of Keycloak, loss of control over the IAM service can affect web applications, mobile applications, and services that depend on centralized sign-on. A direct availability outcome is not established for the exploit path, although abuse of password recovery can prevent legitimate users from signing in.

Business impact

The flaw removes an important control from the account-recovery process. If exploited, an attacker can control a user account and perform actions available to that account in the identity system and dependent applications. Compromise of an administrative account could substantially expand the affected scope, depending on account permissions and SSO integrations. Disabling password recovery as a temporary measure can create support overhead and disrupt legitimate account-recovery workflows.

Remediation

  1. Update Red Hat Build of Keycloak: For standalone deployments, update the 26.4 branch to 26.4.15 or the 26.6 branch to 26.6.6, matching the deployed branch. For containers and OpenShift Operators, deploy the corresponding fixed artifacts tagged 26.4.15-1 or 26.4-23 for the 26.4 branch, and 26.6.6-1 or 26.6-12 for the 26.6 branch. Do not infer the status of another branch from a fix for one branch.
  2. Update Siemens Industrial Edge Management: Update Pro V1 to V1.15.20 or later, Pro V2 to V2.2.2 or later, and Virtual to V2.9.1 or later. For Cloud, confirm the service-side update status described by Siemens.
  3. Temporary Red Hat mitigation: If an immediate upgrade is not possible, disable Forgot password in every realm through Realm settings → Login → Forgot password → Off. This removes legitimate password-reset functionality and is not a replacement for the update.
  4. Temporary Siemens mitigation: Block direct Internet access to IEM Pro or IEM Virtual. If that is not immediately possible, configure a WAF or reverse proxy to block the path /auth/realms/customer/login-actions/reset-credentials after removing the leading space. Blocking the path makes password reset unavailable.
  5. Before applying Red Hat updates, back up the existing installation, including applications, configuration files, databases, and database settings. After updating, verify each realm, image, Operator, and endpoint is running a fixed artifact.

Detection

  1. Inventory standalone Red Hat Build of Keycloak deployments, container images, and Operators, then compare the product branch and build with the fixed boundaries in affected_summary.
  2. In every realm, inspect Realm settings → Login → Forgot password. Enabling this function on an unpatched deployment indicates that the vulnerable recovery flow remains available, but a configuration check does not prove exploitation.
  3. For Siemens Industrial Edge Management, identify whether the deployment is Cloud, Pro V1, Pro V2, or Virtual, verify its version, and determine whether the service is directly exposed to the Internet.
  4. As a precaution, review reverse-proxy, WAF, and Keycloak telemetry for requests to /auth/realms/customer/login-actions/reset-credentials after removing the leading space. This check is based on the endpoint named by Siemens and is not a confirmed IOC.
  5. Review completed password resets, unusual credential changes, and administrative-account activity during the suspected exposure window. Absence of matching log evidence must not be treated as proof of safety.
Sources (26)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan