Weak Password Recovery Mechanism for Forgotten Password Affecting org.keycloak:keycloak-services package, versions [26.0.0,26.7.2)


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
2.79% (86th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGKEYCLOAK-19233600
  • published24 Aug 2026
  • disclosed17 Aug 2026
  • creditUnknown

Introduced: 17 Aug 2026

NewCVE-2026-18963  (opens in a new tab)
CWE-640  (opens in a new tab)

How to fix?

Upgrade org.keycloak:keycloak-services to version 26.7.2 or higher.

Overview

org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services.

Affected versions of this package are vulnerable to Weak Password Recovery Mechanism for Forgotten Password in the ResetCredentialEmail.action() flow in services/src/main/java/org/keycloak/authentication/authenticators/resetcred/ResetCredentialEmail.java. An attacker can force the password reset process for any user by sending a crafted reset-credentials request that reaches the action step without the required email verification link or action token. This lets an unauthenticated attacker advance the authentication session into the password update phase and set new credentials for the target account, resulting in account takeover and loss of control over the user’s account.

CVSS Base Scores

version 4.0
version 3.1