As a proactive security measure, SingleStore has temporarily disabled the Forgot Password workflow in Helios Portal due to a security vulnerability published earlier this week in the community (CVE-2026-18963) and identified in our current version of Keycloak. We are keeping the workflow disabled while we actively upgrade to a version that addresses the issue while maintaining platform stability.
In the meantime, users who authenticate without SSO and have forgotten their password for Portal may contact Support to request a password reset if needed. SSO users are unaffected. The ability to change password while logged in for non-SSO users is also unaffected.
Further note that SingleStore has found no evidence of attempted or successful exploit of this CVE.