FORTBRIDGE identified and reported a vulnerability CVE-2026-18963 affecting Keycloak 26.0.0 through 26.7.1, which allows unauthenticated account takeover via the Forgot password flow without requiring email access or user interaction.
Published
Signal category
Products & Services
Quote
“CVE-2026-18963 - unauthenticated account takeover of any Keycloak user via the 'Forgot password' flow.”
— FORTBRIDGE team
Company
FORTBRIDGE
FORTBRIDGE – Leading IT Security Services in London | Cybersecurity, Penetration Testing, Red Teaming and Cloud Security
- Industry
- Computer and Network Security
- Location
- London, GB
- Company size
- 5 employees
Every engagement led by consultants with 10-20 years of offensive security experience. No juniors. No outsourcing. No bait-and-switch. FORTBRIDGE is a CREST and DESC accredited penetration testing firm based in London, UK. We specialise in identifying and mitigating vulnerabilities across web applications, APIs, mobile apps, cloud environments, and AI/LLM systems. What sets us apart: every assessment is executed start-to-finish by senior consultants holding elite certifications (OSCP, OSWE, CRTO, CRTL, AWS/Azure/GCP). You communicate directly with the tester - no account managers, no go-betweens. Our research has been featured in The Guardian, Market Watch, The Register, and more. Our Services Include: ➤ Web Application Penetration Testing ➤ Mobile & API Penetration Testing ➤ Cloud Security Assessment ➤ Red Teaming ➤ Network Penetration Testing ➤ Security Architecture Review ➤ Phishing Simulations ➤ LLM Security Testing ➤ White Box Penetration Testing As a family-run business, security is in our blood. We work with organisations from startups to FTSE 100 companies. For more information, contact FORTBRIDGE today.
Founded 2020