CVE-2026-18963

EUVD-2026-61063
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 87.61%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
SiemensIndustrial Edge Management Cloud
𝑥
< *
ADP
SiemensIndustrial Edge Management Pro V1
V1.14.9 ≤
𝑥
< V1.15.20
ADP
SiemensIndustrial Edge Management Pro V2
V2.2.0 ≤
𝑥
< V2.2.2
ADP
SiemensIndustrial Edge Management Virtual
V2.6.0 ≤
𝑥
< V2.9.1
ADP