Critical Keycloak Password Reset Flaw Could Let Attackers Hijack Any Account
A critical vulnerability rated 9.1 CVSS in Keycloak allows unauthenticated attackers to hijack user accounts by forcing password resets, with patches released by Red Hat and the Keycloak project.