Skip to content

SecurityNot yet confirmed elsewhere1 publisher2 min readPublished

Three items, one tier: Keycloak's reset bug, an N-able password leak, a Grok data-theft trick

A single Stormcast episode carries a Keycloak 26.7.2 password-reset fix, a reported N-able password manager leak, and a published LLM safeguard bypass. Most of it sits in the identity and secrets tier.

The Watch · Security desk

How we use AISend a correction

Photograph accompanying Three items, one tier: Keycloak's reset bug, an N-able password leak, a Grok data-theft trick
Photo: isc.sans.edu

What happened

  • One of them closes a password reset bug that allowed an unauthenticated user to reset any user's password.
  • The verification token mailed to the account holder was not properly validated, so it could be spoofed by an attacker who never saw the email.
  • It also linked an adversa.ai post by Ronnie Utevsky on cryptographic context injection, presented as data theft against Grok.

Why it matters

  • exposure Operators who never chose Keycloak still own its reset bug, because it arrives inside another vendor's product and rarely appears in their own inventory.
  • decision There is no compensating control to buy time with here: stronger passwords and mailbox hygiene do not touch this path, so the upgrade is the only lever in evidence.
  • capability Identity inventory becomes a scripted query, and it cuts both ways: whoever holds Graph read scope gets the dormant accounts and the tenant's own risk verdicts in one pull.
  • precedent A password manager sold as security tooling landing in the same day's column as an IAM patch pushes vendor-held secret stores toward default rotation scope after any vendor incident.

Every password reset flow is a second authentication path, usually with one factor holding it up. In Keycloak that factor was the emailed token, and with the token not properly validated the path would accept anonymous requests to change any user's password [2]. No other part of the stack was asked to agree.

Then there is distribution. Keycloak is rarely a purchase decision; it is the identity and access management layer sitting under other products and web applications, with Red Hat using it heavily and supporting its development [7]. Upstream exists as 26.7.2, with a number of security fixes in it [1], but an operator running Keycloak inside somebody else's appliance gets those fixes on the vendor's rebuild schedule [10].

Discovery was not systematic either. Johannes Ullrich credited a listener named Daniel for pointing the issue out, and said he would probably have missed it otherwise [8]. Release notes for embedded identity components are read by very few people, and that is the channel this one travelled down.

The other two items in the same episode are, in the material available, links with headlines attached. Ronnie Utevsky's post at adversa.ai describes what he calls cryptographic context injection, presented as a way around safeguards in large language models and framed in both the episode title and the link itself as data theft against Grok [3]. The transcript stops mid-sentence before the method is explained [13], so it is a pointer rather than a finding. The N-able entry is filed as a password manager leak and points at a post whose own URL calls it SolarWinds part two [4].

The Microsoft Graph diaries alongside them are hygiene work: two PowerShell scripts from Rob, one listing users with stale accounts and the licenses assigned to them, the other collecting Entra risk detections with the reason each was raised, including unusual browser user agents and origin by geography or ASN [5]. Stale accounts belong to the same tier as the Keycloak bug. A dormant account still has a reset flow wired to a mailbox nobody reads, and it still holds whatever roles it was handed.

Four topics in one episode, three of them about the machinery that holds credentials [12]. Token validation is the entire Keycloak fix, which is the least interesting class of finding and the one that reaches furthest.

What to watch

  • Whether Keycloak assigns a CVE and severity to the reset flaw, and how quickly vendors embedding Keycloak rebuild on 26.7.2.
  • Detail from N-able on the scope of the password manager exposure and whether stored customer credentials need rotation.
  • Whether the cryptographic context injection method reproduces against assistants other than Grok, and any response from xAI.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence52
Adoption
Insufficient
Hype gap+14
Incentives34
Confidence55
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Keycloak released version 26.7.2, fixing a number of security vulnerabilities.

    ReportedSupportedSource: SANS Internet Storm Center Stormcast, 21 August 20262 sources— create a free account to open themView cited source
  2. [2]

    One of the vulnerabilities fixed in Keycloak 26.7.2 is a password reset issue in which an unauthenticated user is able to reset any user's password.

    ReportedSupportedSource: Johannes Ullrich, SANS ISC Stormcast2 sources— create a free account to open themView cited source
  3. [3]

    The episode links a blog post at adversa.ai by Ronnie Utevsky describing what he calls cryptographic context injection, a way to bypass safeguards in large language models; the episode title and the linked URL present it as Grok data theft.

    ReportedSupportedSource: Ronnie Utevsky via adversa.ai, as summarised in the Stormcast2 sources— create a free account to open themView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. isc.sans.edu

    1 article · August 26, 2026

    SANS Stormcast Friday, August 21st, 2026: Microsoft Graph and Powershell; Keycloak Vuln; Cryptographic Context Injection; N-Able Password Leak

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories