Keycloak CVE-2026-18963 could let unauthenticated attackers skip the emailed action token and reset any user's password.
I reached a point in my homelab journey where it started to feel like I was logging in with similar credentials for separate services. I always liked the idea of one centralized authentication. I was ...