Keycloak CVE-2026-18963 Lets Unauthenticated Attackers Reset Any Account Password
Keycloak CVE-2026-18963 lets unauthenticated attackers reset any user's password without the email verification link. The flaw carries a 9.1 CVSS score and affects every deployment using the default password reset flow.