CVE-2026-18963
CVSS 9.1 CRITICAL: a flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. EPSS 3% (87th percentile).
Vulnerabilities · 8h ago
CISA said Siemens Industrial Edge Management has an authentication-bypass flaw, CVE-2026-18963, that lets an unauthenticated remote attacker take over user accounts by resetting credentials without completing email verification. The advisory covers Industrial Edge Management Cloud, Pro V1, Pro V2, and Virtual, and Siemens has released fixed versions for the affected builds.
The bug sits in the reset-credentials flow in the Keycloak-based identity layer, so the attacker does not need the email link that normally proves account ownership. By forcing the password reset path and setting a new password, the reset page itself becomes the login bypass, which means the exposure starts at identity and can extend into whatever the compromised account administers.
For operators, the important boundary is where authentication sits in front of fleet management: if that gate is reachable, patching is what closes the takeover path, while any device-only view of the problem misses the real entry point. The same reset-flow trust break also matters anywhere Keycloak-backed portals rely on email verification to prove ownership.
CVSS 9.1 CRITICAL: a flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. EPSS 3% (87th percentile).
1 source covering this story
Siemens Industrial Edge Management | CISA
Siemens Industrial Edge Management Summary Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification.
Part of the PlainSec briefing for 2026-09-22