Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
Keycloak CVE-2026-18963 could let unauthenticated attackers skip the emailed action token and reset any user's password.
More info
