Tartışma

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Başlatan The Hacker News · 24 Ağu 2026 15:31 · 23 Görüntülenme · 0 Yanıtlar
Konuyu Açan #0
Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset.

The vulnerability, assigned the CVE identifier CVE-2026-18963, is rated 9.1 on the CVSS scoring system by Red Hat, which acts as

Okumaya devam et...

Yanıt vermek için giriş yapmış olmalısınız.

0 alıntı seçildi