Impact
A flaw in the reset-credentials flow of the Keycloak‑services component allows an attacker who is not authenticated to force a password reset for any user. By bypassing the required email verification link, the attacker can directly set new credentials for the target account and thereby gain full control over that account, compromising confidentiality, integrity, and availability of the affected identity services.
Affected Systems
This vulnerability impacts Red Hat Build of Keycloak versions 26.4, 264.15, 26.6, 26.6.6, as well as the Red Hat JBoss Enterprise Application Platform Expansion Pack and Red Hat Single Sign‑On 7, all of which rely on the keycloak-services component for resetting credentials.
Risk and Exploitability
The CVSS score of 9.1 classifies this flaw as critical, and an EPSS score of 3 % indicates a moderate likelihood of exploitation in the wild. It is not currently listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector involves unauthenticated HTTP requests to the reset‑credentials endpoint from any system that can reach the Keycloak Services deployment; this can be performed without user interaction. If exploited, an attacker can hijack user accounts and potentially move laterally within the environment.
OpenCVE Enrichment
Github GHSA