Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
A critical security flaw in Keycloak's password reset feature allows unauthenticated attackers to take over any user account by forcing a password reset. Red Hat has released patches to address the issue.
Intelligence analysis by Llama

A vulnerability in Keycloak's password reset feature allows unauthenticated attackers to take over any user account. Red Hat has released patches to address the issue.
Imagine you have a secret password to keep your account safe. But, there's a way for someone to guess your password and take control of your account without even knowing your password. This is what happened with Keycloak's password reset feature. It's like a backdoor that lets someone in without a key.
Analysis
Root Cause of the Flaw
The root cause of the flaw is improper state validation within the reset-credentials authentication flow in Keycloak. This flow is triggered when a user requests password recovery. An attacker can exploit this flaw by sending a specially crafted request to the reset-credentials endpoint, which transitions directly to the password update phase without requiring the action token that Keycloak normally sends via email.
Impact of the Flaw
The flaw allows an unauthenticated remote attacker to take over any user account, including administrative accounts, by resetting their password. This is a critical security issue, as it enables an attacker to gain unauthorized access to sensitive information and potentially disrupt business operations.
Patching the Flaw
Red Hat has released patches to address the issue, including updates for the standalone server packages and container images for two RHBK streams. Users of upstream Keycloak are advised to update to version 26.7.2, while customers running Red Hat build of Keycloak (RHBK) should apply the updates shipped for 26.4.15 and 26.6.6. In the meantime, Red Hat has published a temporary mitigation – turning off the "Forgot password" functionality across all realms.
Key points
- A critical security flaw in Keycloak's password reset feature allows unauthenticated attackers to take over any user account.
- Red Hat has released patches to address the issue, including updates for the standalone server packages and container images for two RHBK streams.
- Users of upstream Keycloak are advised to update to version 26.7.2, while customers running Red Hat build of Keycloak (RHBK) should apply the updates shipped for 26.4.15 and 26.6.6.
- A temporary mitigation has been published – turning off the "Forgot password" functionality across all realms.
If this flaw is patched quickly, users can rest assured that their accounts are secure. Red Hat's prompt response to address the issue demonstrates their commitment to security and customer trust.
If the flaw is not patched promptly, it could lead to a significant security breach, compromising sensitive information and disrupting business operations. This would be a major setback for Keycloak users and could damage the reputation of the platform.



