Re-authentication is missing while updating the password. This may cause account takeover if any attacker get the temporary physical access to a user's browser. https://issues.redhat.com/browse/KEYCLOAK-17250
No Red Hat product other than RHSSO has this account console feature so marking all of them as not affected.
Acknowledgments: Name: Tuan Tran (mgm security partners GmbH)