天下漏洞,尽知其名
CRITICAL

CVE-2026-18963 Red Hat Build of Keycloak 账户接管漏洞

影响未认证攻击者可重置任意用户密码并接管账户

AI 研判

该漏洞存在于 Red Hat Build of Keycloak 的 keycloak-services 组件凭据重置流程中。攻击者无需点击邮件验证链接即可强制触发任意用户的密码重置流程,并直接设置新凭据。成功利用后可完全控制目标用户账户。

影响范围

Red Hat Build of Keycloak

受影响组件为 Red Hat Build of Keycloak 的 keycloak-services 组件,具体受影响版本范围暂无公开信息。

漏洞详情

漏洞类型为身份认证绕过/账户接管。成因在于凭据重置流程未正确校验邮件验证链接这一必要步骤,导致未认证攻击者可跳过验证直接完成密码重置。攻击者只需知道目标用户名即可发起请求并设置新密码,从而接管账户。

利用条件与风险

利用无需认证,仅需目标用户名,攻击门槛低;一旦成功可接管任意用户账户,若目标为管理员则可能导致整个身份认证体系失陷,实战风险极高。

修复建议

建议关注 Red Hat 官方针对 CVE-2026-18963 发布的安全公告并升级至修复版本;在补丁可用前,可限制凭据重置接口访问、加强邮件验证流程校验或临时禁用相关重置功能作为缓解措施。具体修复方案以官方公告为准。

原始情报

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.