Skip to main content
Question

Question regarding the Keycloak Vulnerability Advisory (CVE-2026-18963)

  • September 7, 2026
  • 0 replies
  • 3 views

Forum|alt.badge.img+1

Hello, 

 

We recently received an advisory from IFS relating to a vulnerability in the ‘forgot password’ function (CVE-2026-18963) - https://support.ifs.com/csm?id=kb_article_view&sys_kb_id=0e7c67922bc347507377f6bcf291bf11&table=kb_knowledge&sysparm_article=KB0100589

 

I have applied the mitigation script to our test environment without issue - but I have one question before processing further. Does anyone know if the mitigation fix is permanent or is undone every time the IFSIAM pod is recreated (which I believe is done every time the middle tier is restarted with mtctl)? 

 

Thanks, 

Joe