CVE-2026-19611
Red Hat Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Debezium 3, Red Hat Build of Keycloak
A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only dictionary against accounts whose passwords were intended to include those non-ASCII characters, leading to unauthorized access.
- CVSS
- 7.4
- EPSS
- 0.34% 27.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.08.21