CVE-2026-18963
CVSS 9.1 CRITICAL: a flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. EPSS 3% (87º percentile).
Vulnerabilità ed exploit · Furto di credenziali
Siemens ha corretto CVE-2026-18963 in Industrial Edge Management Cloud, Pro V1, Pro V2 e Virtual. La falla consente a un attaccante non autenticato di prendere il controllo di un account senza superare la verifica email, quindi il punto debole non è il server esposto ma il flusso di identità davanti alla gestione industriale.
Il problema sta nel reset-credentials di Keycloak: il processo di recupero password può essere forzato e chi attacca può impostare nuove credenziali al posto dell’utente legittimo. In pratica, la pagina di reset diventa una scorciatoia per l’accesso, con impatto diretto su chi amministra la flotta e sugli account che governano i sistemi edge.
Per chi usa portali basati su Keycloak o flussi di reset email-verified, il caso mostra che il controllo del percorso di recupero è parte del perimetro. Una correzione del bug non basta se l’interfaccia di reset resta raggiungibile o esposta fuori controllo.
1 fonte · 9 ore fa
CVSS 9.1 CRITICAL: a flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. EPSS 3% (87º percentile).
CISA Advisories
Siemens Industrial Edge Management | CISA
Siemens Industrial Edge Management Summary Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification.
originalePart of the PlainSec briefing for 2026-09-22
Every edition of this story: Il reset password diventa takeover su Siemens Industrial Edge Management