RHSA-2026:56519CriticalCVSS 9.1

Red Hat Security Advisory: Red Hat build of Keycloak 26.4.15 Images Security Update

Published
August 18, 2026
Last Modified
August 20, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-18963 — keycloak-services: keycloak-services: Unauthenticated account takeover via reset-credentials flow bypass

🎯 Affected products10

  • Red Hat build of Keycloak 26.4
  • rhbk/keycloak-operator-bundle@sha256:f4df815564fc6801b50dffbbd3e0a421dfd83841c83c22a8e09305eeffdaf687_amd64 as a component of Red Hat build of Keycloak 26.4
  • rhbk/keycloak-rhel9-operator@sha256:32c3da0c9e63f7a86ae49255fbcf318406bb3e34ee07f1bae7e1dc01c6329efd_arm64 as a component of Red Hat build of Keycloak 26.4
  • rhbk/keycloak-rhel9-operator@sha256:9b5001e9dde3cd87823988cafd809a5887b296c048e398171e28b1c256de1107_ppc64le as a component of Red Hat build of Keycloak 26.4
  • rhbk/keycloak-rhel9-operator@sha256:b72782f1fbc44144e58f08884b5a6f9a3a49e32c1965a9ce3d01bd6f70e761f8_s390x as a component of Red Hat build of Keycloak 26.4
  • rhbk/keycloak-rhel9-operator@sha256:b80c873fd9fe1ec85cf4191714a6ea2ac80854b2bdc3781d15811d16692527a0_amd64 as a component of Red Hat build of Keycloak 26.4
  • rhbk/keycloak-rhel9@sha256:5ae22f5c60ebeab633caa0ac3e3540402e9d589409513c67c2b1dada998c178d_ppc64le as a component of Red Hat build of Keycloak 26.4
  • rhbk/keycloak-rhel9@sha256:696cf024e6bb736260b7a2439cc9e7b3aa05024c8c493ae6e448b224718e464b_amd64 as a component of Red Hat build of Keycloak 26.4
  • rhbk/keycloak-rhel9@sha256:8918c47378bb686b0894188d6ad578e5ce469def4926c419194703237a2fee3d_s390x as a component of Red Hat build of Keycloak 26.4
  • rhbk/keycloak-rhel9@sha256:faf3f6772c31b33f526887927505095a6dd5bd8e507c643ebcc64eea60be56eb_arm64 as a component of Red Hat build of Keycloak 26.4

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Workaround: If an immediate upgrade is not possible, disabling the "Forgot password" functionality across all realms can be used as a temporary mitigation. In the RHBK administration console, navigate to: Realm settings → Login → Forgot password → Off Apply this setting to all realms. Upgrade to a fixed version as soon as possible.

🔗 References (3)