SECURITY·중요도 9·2026. 08. 24.·The Hacker News
Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
── KO ──────────────────
중요한 Keycloak 비밀번호 초기화 취약점이 발견되어 패치가 배포됐다.
Red Hat과 Keycloak 프로젝트는 인증되지 않은 원격 공격자가 사용자의 계정을 장악할 수 있는 심각한 비밀번호 초기화 취약점에 대한 패치를 발표했다. 이 취약점은 CVE-2026-18963로 지정되었으며, CVSS 점수는 9.1로 평가받았다. 따라서 사용자는 즉시 보안 업데이트를 적용하여 위험을 최소화해야 할 필요가 있다.
── EN ──────────────────
A critical Keycloak password reset flaw allows unauthenticated attackers to take over accounts.
Red Hat and the Keycloak project have released patches for a critical vulnerability that allows an unauthenticated remote attacker to take over any user account by forcing a password reset. The flaw is assigned the CVE ID CVE-2026-18963 and is rated 9.1 on the CVSS scoring system. Users are advised to apply the security updates promptly to minimize risks.