Siemens' Edge Platform Still Carried a Keycloak Bug Fixed in August
Security / news
Siemens' Edge Platform Still Carried a Keycloak Bug Fixed in August
CISA published the advisory on Sept. 22, more than a month after Red Hat shipped the upstream fix, because four Siemens Industrial Edge Management products bundle the identity server.

An unauthenticated attacker with network access to Siemens Industrial Edge Management could force a password reset for any account, including an administrator's, and set new credentials directly, without ever clicking the email verification link the reset flow is supposed to require. Siemens' advisory, republished by CISA on Sept. 22, rates the flaw 9.1 out of 10 on the CVSS scale. The bug itself was fixed upstream more than a month earlier, on Aug. 19.
The bug belongs to Keycloak, not to Siemens
Industrial Edge Management uses Keycloak, the open-source identity and access management server originally built by Red Hat, to handle logins. The flaw, tracked as CVE-2026-18963, sits in Keycloak's own reset-credentials flow. Red Hat's advisory describes the root cause as improper state validation that lets a crafted request skip straight to the password-setting stage without completing the required email-based verification step, and credits a researcher named James Paremain with reporting it. Red Hat shipped the fix in upstream Keycloak 26.7.2 on Aug. 19 and in Red Hat build of Keycloak bundles 26.4.15 and 26.6.6 around the same time.

Four products, one shared component
Siemens said the flaw reaches its Industrial Edge Management Cloud service and three on-premises variants: Pro V1 before 1.15.20, Pro V2 before 2.2.2, and Virtual before 2.9.1. Each bundles its own copy of Keycloak rather than pointing at a shared, centrally patched instance, which is why a fix that shipped for the underlying project on Aug. 19 did not reach every Siemens deployment on the same day.
| Product | Affected versions | Fixed version |
|---|---|---|
| Industrial Edge Management Cloud | All versions | Update pending, per advisory |
| Pro V1 | Before 1.15.20 | 1.15.20 |
| Pro V2 | Before 2.2.2 | 2.2.2 |
| Virtual | Before 2.9.1 | 2.9.1 |
A gap CISA's advisory does not explain
CISA's republication, five weeks after Red Hat's own fix, does not say whether Siemens learned of the upstream bug when Red Hat disclosed it in August or only later, and it does not report any exploitation of the flaw in Siemens' products specifically. Industrial Edge Management is Siemens' platform for managing edge computing devices on factory floors, which means the accounts it protects can include the ones that manage physical equipment, not just dashboards.
What operators can do before every product line has a fix
Siemens' advisory lists three mitigations for anyone who cannot patch immediately: block internet access to the affected management interface, deploy a web application firewall or reverse proxy rule blocking the specific path /auth/realms/customer/login-actions/reset-credentials, and disable the password-reset feature in Keycloak's own configuration entirely until an update is applied. For the on-premises Pro and Virtual editions, updating to the versions in the table above removes the exposure directly. The pattern is one The Terminal has tracked before in industrial vendors' advisories: a hardcoded credential in AVEVA's pipeline software and a Hitachi Energy flaw with no patch version yet available both showed the same lag between when a component's maintainer fixes something and when the industrial vendor bundling it catches up.
Sources
More in Security
- 01LuaRocks Patches a Bytecode Flaw Attackers Used for Six WeeksAn independent researcher's writeup, published a day after the fix, names the LuaJIT instruction that let a crafted package listing read and write server memory.
- 02Graphalgo Malware Reaches Terraform Providers for the First TimeTwo fake Terraform providers and two Go modules polled an Ethereum contract every 3 seconds as a backup channel, security firm Aikido said, describing the campaign's first use of HashiCorp's registry.
- 03CISA's WSO2 Catalog Entry Names the Wrong VulnerabilityThe agency's Sept. 24 addition of CVE-2026-5430 borrows language from a different, four-year-old WSO2 flaw, even as watchTowr reports live attacks forging admin tokens through the real one.
- 04Microsoft's SharePoint 'Spoofing' Bug Is Really an RCE FlawCVE-2026-65660 sat rated 6.5 for weeks until a Viettel researcher showed it grants remote code execution, and CISA added it to its exploited-vulnerabilities catalog Sept. 25 after attackers began installing webshells.