Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

A Critical Flaw in Keycloak Exposes Millions of Users to Account Takeover Attacks

A severe vulnerability has been discovered in Keycloak, a popular open-source identity and access management platform used by millions of organizations worldwide. The flaw, which allows unauthenticated attackers to reset passwords for any account, poses a significant risk to the security of users’ sensitive information. Keycloak’s widespread adoption across industries, including finance, healthcare, and government, makes this vulnerability particularly concerning.

Keycloak is designed to manage user identities, authenticate access, and authorize actions within an organization’s systems. It provides a single sign-on (SSO) experience for employees and external partners, streamlining access to various applications and services. However, the recently discovered flaw enables attackers to bypass Keycloak’s authentication mechanisms, allowing them to reset passwords for any account without needing credentials.

The vulnerability works by exploiting a misconfigured password reset feature in Keycloak. Normally, when a user requests a password reset, they’re required to provide their email address or username associated with the account. However, if this configuration is not properly set up, an attacker can exploit it by manipulating the URL used for password resets. This allows them to gain access to any account without authenticating.

The severity of this vulnerability cannot be overstated. Keycloak’s large user base and widespread adoption across industries make it a prime target for attackers seeking to compromise sensitive information. An attacker who gains control of an account can perform various malicious activities, such as accessing confidential data, modifying settings, or even selling the compromised credentials on the dark web.

The discovery of this vulnerability highlights the importance of proper configuration and maintenance of identity management systems like Keycloak. Organizations relying on Keycloak must ensure that they have implemented the necessary security measures to prevent attackers from exploiting this flaw. This includes regularly reviewing and updating configurations, as well as conducting thorough security audits to identify potential vulnerabilities.

To protect themselves from similar attacks in the future, users should be cautious when using public computers or unsecured networks for password resets or other sensitive activities. They should also ensure that their organization’s identity management systems are properly configured and maintained by trained professionals. By staying vigilant and taking proactive measures, individuals can significantly reduce their risk of falling victim to account takeover attacks.


Source: The Hacker News — 2026-08-24