Skip to content
  • There are no suggestions because the search field is empty.

Critical Security Advisory: CVE-2026-18963 Keycloak Vulnerability (Action Recommended)

We're notifying you of a critical vulnerability (CVE-2026-18963, CVSS 9.1) in Keycloak, AtScale's authentication component, which affects all Container releases prior to C2026.8.0 and could allow account takeover via the password-reset flow; details and an interim mitigation are below.

Important details below:


Security Advisory: Keycloak password-reset vulnerability (CVE-2026-18963)

Severity: Critical (CVSS 9.1)

Affected: All AtScale Container releases prior to C2026.8.0

Resolved in: C2026.8.0 (Pending Release - Target is early September)


Summary

A critical vulnerability (CVE-2026-18963) has been identified in Keycloak, the component AtScale uses for authentication. The flaw is in the password-reset flow: an unauthenticated attacker can trigger a password reset for any user and complete it without the email-verification step, potentially leading to account takeover.


This affects all AtScale releases prior to C2026.8.0.


Resolution

The fix is included in AtScale C2026.8.0; we recommend upgrading to C2026.8.0 (or later) as soon as it's available.


Interim mitigation

Exposure can be mitigated by disabling the "Forgot password" option in each realm. This is disabled by default. The setting can be reviewed and disabled in the AtScale UI:


Security > Configure > Realm settings > Login tab > disable the "Forgot password" option



Apply this to every realm used for user login. With the option disabled, the vulnerable self-service reset flow is unavailable. Users who need a password reset will need an administrator to perform it for them. After you upgrade to C2026.8.0, you can re-enable the option if needed.


As an alternative or additional safeguard, requiring MFA on your realms also protects against this attack.


Questions

If you need help applying the mitigation or planning an upgrade, please contact support.

AtScale Footer