Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CVE-2026-18963 — Detection and verification tool for CVE-2026-18963, a Keycloak reset-credentials state bypass. Performs version fingerprinting, realm/client/user enumeration, and tests whether the action-token precondition is enforced, for authorized assessments. | Kitploit
أدوات/GitHubGitHub/alt3kx/cve-2026-18963
ReconnaissanceVulnerability AnalysisExploitationInformation GatheringWeb SecurityPenetration TestingAuthentication
GitHubalt3kx/cve-2026-18963

CVE-2026-18963

Detection and verification tool for CVE-2026-18963, a Keycloak reset-credentials state bypass. Performs version fingerprinting, realm/client/user enumeration, and tests whether the action-token precondition is enforced, for authorized assessments.

عرض المستودع
419منذ 20 أياملم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
الموقع الإلكتروني
المحتوى غير متوفر باللغة المطلوبة. عرض النسخة الإنجليزية.

CVE-2026-18963 Keycloak Reset-Credentials State Bypass Detector

https://github.com/user-attachments/assets/005fab89-339a-4e4e-881c-da6a626f6c9e

root@kitploit:~
python3 kc-resetforge.py -h


usage: kc-resetforge.py [-h] [--target TARGET] [--targets-file TARGETS_FILE] [--port PORT] [--realm REALM]
                        [--client-id CLIENT_ID] [--username USERNAME] [--new-password NEW_PASSWORD] [--skip-enum]
                        [--enum-only] [--kc-version] [--kc-reset-link] [--corpus-dir CORPUS_DIR] [--label LABEL]
                        [--enum-realms] [--no-enum-realms] [--enum-clients] [--no-enum-clients] [--enum-users]
                        [--no-enum-users] [--realm-wordlist REALM_WORDLIST] [--client-wordlist CLIENT_WORDLIST]
                        [--user-wordlist USER_WORDLIST] [--enum-users-client-id ENUM_USERS_CLIENT_ID]
                        [--verify-login] [--no-verify-login] [--verify-client-id VERIFY_CLIENT_ID]
                        [--timeout TIMEOUT] [--request-delay REQUEST_DELAY] [--output-dir OUTPUT_DIR]
                        [--proxy PROXY] [-d] [-y] [--json-out JSON_OUT]

CVE-2026-18963 Keycloak recon + exploit framework (own infra only)

options:
  -h, --help            show this help message and exit
  --target TARGET       Single target: bare host/IP, host:port, or a full http(s)://host[:port] URL. Scheme and port
                        are auto-detected if omitted (tries https then http; defaults to 443/80 respectively).
                        Mutually exclusive with --targets-file.
  --targets-file TARGETS_FILE
                        Path to a file with one target per line, same flexible formats as --target ('#' comments
                        allowed). Runs recon+exploit against every target in turn.
  --port PORT           Override port for --target (or a fallback for --targets-file lines without their own port).
                        Per-line ports in --targets-file always take precedence.
  --realm REALM         Realm to target. If omitted, auto-selected from recon results.
  --client-id CLIENT_ID
                        OIDC client_id to use. If omitted, auto-selected from recon results.
  --username USERNAME   Username to target. If omitted, auto-selected from recon results.
  --new-password NEW_PASSWORD
                        Password to set for the target user (default: 'Test123!')
  --skip-enum           Skip recon entirely; --realm/--client-id/--username become required.
  --enum-only           Run recon and print results, but do not attempt exploitation.
  --kc-version          Only run the Keycloak version recon phase (fingerprint + corpus match + patch status) and
                        exit - skips realm/client/user enumeration and exploitation entirely. Works with both
                        --target and --targets-file.
  --kc-reset-link       Only check whether the self-service password-reset ('Forgot Password?' /
                        resetPasswordAllowed) flow is exposed, then exit - a single non-destructive GET, no username
                        needed. Auto-discovers realm/client via a light realm+client recon unless --realm/--client-
                        id are given explicitly. Skips exploitation. Works with both --target and --targets-file.
  --corpus-dir CORPUS_DIR
                        Directory of known-version fingerprints for exact version matching (default:
                        kc_version_corpus).
  --label LABEL         Save THIS target's fingerprint into the corpus under this version label instead of matching
                        an unknown version. Use on an instance of known version.
  --enum-realms         Enumerate realm names (default: on during recon).
  --no-enum-realms
  --enum-clients        Enumerate client IDs per realm (default: on during recon).
  --no-enum-clients
  --enum-users          Enumerate usernames per realm (default: on during recon).
  --no-enum-users
  --realm-wordlist REALM_WORDLIST
  --client-wordlist CLIENT_WORDLIST
  --user-wordlist USER_WORDLIST
  --enum-users-client-id ENUM_USERS_CLIENT_ID
                        Client used for the username-enumeration direct-grant probe (default: admin-cli).
  --verify-login        After a password change, confirm the new credentials via a password-grant token request
                        (default: on).
  --no-verify-login
  --verify-client-id VERIFY_CLIENT_ID
                        Client used for the verification password grant.
  --timeout TIMEOUT
  --request-delay REQUEST_DELAY
                        Seconds to wait before each request in the exploit chain (default: 0.4). Keycloak's login-
                        flow state can be timing-sensitive across the reset/restart/selector replay steps; a small
                        delay makes the chain more reliable. 0 to disable.
  --output-dir OUTPUT_DIR
  --proxy PROXY         Route through an HTTP(S) proxy: 'burp' (127.0.0.1:8080 shorthand), a bare host:port, or a
                        full http(s):// URL.
  -d, --debug           Verbose debug logging of requests/responses/enum probes
  -y, --yes             Skip the 'Continue with this target?' prompt. Required for non-interactive use (scripts,
                        --targets-file with multiple targets, CI).
  --json-out JSON_OUT   Write a JSON report of recon + exploit results to this path.

kc-resetforge — CVE-2026-18963 Keycloak recon + exploit tool (own infra only)

Usage
-----
Fully automatic (recon -> auto-pick target -> exploit -> verify):
    python3 kc-resetforge.py --target https://localhost:9990 --proxy burp -d

Recon only:
    python3 kc-resetforge.py --target https://localhost:9990 --enum-only -d

Version + patch-status check only, across many hosts:
    python3 kc-resetforge.py --targets-file targets.txt --kc-version

Skip recon, target directly:
    python3 kc-resetforge.py --target https://localhost:9990 --realm master \
        --client-id account --username admin --skip-enum

Requires: requests, beautifulsoup4, and optionally rich (pip install --break-system-packages)

Vulnerability Summary

Technical Details

  • Root cause: improper state validation in the reset-credentials flow. The server tracks which step a session is on but does not independently re-verify that the emailed action-token step was actually completed before allowing the flow to advance to password update.
  • Preconditions: none — unauthenticated, no user interaction, no prior access required.
  • Scope: any realm with "Forgot password" enabled, pre-26.7.2.
  • Fix:
    • Upstream Keycloak 26.7.2
    • RHBK 26.4 → operator bundle 26.4.15-1 / images 26.4-23
    • RHBK 26.6 → operator bundle 26.6.6-1 / images 26.6-12
    • Interim mitigation: disable "Forgot password" per realm (Realm Settings → Login → Forgot password)

About This Tool

kc-resetforge is a detection/verification tool. It confirms whether a target's reset-credentials flow enforces the action-token precondition correctly (patched) or not (vulnerable), for use in authorized assessments. The write-up linked below covers the mechanism and reproduction methodology at the depth appropriate for public disclosure.

Full analysis: Forging kc-resetforge: Turning CVE-2026-18963 Into a Repeatable Check

Version identification

kc-resetforge.py can't ask Keycloak "what version are you?", there's no pre-auth endpoint that answers that. Instead it fingerprints a target (response fields, static asset hashes, favicon) and compares it against a corpus of fingerprints you've already labeled with a known version. No corpus entry for that fingerprint = no exact version, by design, not a bug.

Build the corpus once per version you have access to:

root@kitploit:~
python3 kc-resetforge.py --target https://known-26.6.2-host --kc-version --label 26.6.2
python3 kc-resetforge.py --target https://known-26.7.2-host --kc-version --label 26.7.2
[snip]

My Lab:
python3 kc-resetforge.py --target https://localhost:9990 --kc-version --label 26.6.2
python3 kc-resetforge.py --target https://localhost:9991 --kc-version --label 26.6.3
python3 kc-resetforge.py --target https://localhost:9992 --kc-version --label 26.6.4
python3 kc-resetforge.py --target https://localhost:9993 --kc-version --label 26.7.0
python3 kc-resetforge.py --target https://localhost:9994 --kc-version --label 26.7.1
python3 kc-resetforge.py --target https://localhost:9995 --kc-version --label 26.7.2

Recon:
python3 kc-resetforge.py --targets-file targets.txt --kc-version --kc-reset-link --proxy 127.0.0.1:8080
[snip]

[*] Proxying through: http://127.0.0.1:8080
[+] Run Summary
Targets scanned

┏━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━┳━━━━━━━━━━━━┳━━━━━━━━┓
┃Target                 ┃ Keycloak Version ┃ Patch      ┃ Reset Link ┃ Result ┃
┡━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━╇━━━━━━━━━━━━╇━━━━━━━━┩
│https://localhost:9990 │ 26.6.2           │ VULNERABLE │ ENABLED    │ checked│
│https://localhost:9991 │ 26.6.3           │ VULNERABLE │ ENABLED    │ checked│
│https://localhost:9992 │ 26.6.4           │ VULNERABLE │ ENABLED    │ checked│
│https://localhost:9993 │ 26.7.0           │ VULNERABLE │ ENABLED    │ checked│
│https://localhost:9994 │ 26.7.1           │ VULNERABLE │ ENABLED    │ checked│
│https://localhost:9995 │ 26.7.2           │ PATCHED    │ ENABLED    │ checked│
└───────────────────────┴──────────────────┴────────────┴────────────┴────────┘

Entries are saved next to the script, in kc_version_corpus/, so they persist regardless of which directory you run the tool from , don't delete that folder.

Check what's in the corpus:

root@kitploit:~
ls kc_version_corpus/

Once labeled, every future scan auto-matches against it:

root@kitploit:~
python3 kc-resetforge.py --target https://target --kc-version
python3 kc-resetforge.py --targets-file targets.txt --kc-version

Credits

Vulnerability Discovery

  • James Paremain (credited in Red Hat's advisory)

Tool

  • Alex Hernandez aka (@_alt3kx_)

References

  • https://access.redhat.com/security/cve/CVE-2026-18963
  • https://www.keycloak.org/2026/08/keycloak-2672-released
  • https://thehackernews.com/2026/08/critical-keycloak-password-reset-flaw.html
  • https://github.com/keycloak/keycloak/issues/51833

Disclaimer

This project is provided strictly for:

  • Authorized security assessments
  • Defensive testing
  • Educational research

Do not run this tool against any system you do not own or have explicit written authorization to test. Unauthorized use against third-party infrastructure is illegal and outside the intended purpose of this project. The maintainer assumes no liability for misuse.

تنزيل الأداة
FieldValue
CVECVE-2026-18963
SeverityCritical
CVSS9.1
CWECWE-640 (Weak Password Recovery Mechanism)
ComponentKeycloak — reset-credentials authentication flow
ImpactUnauthenticated, zero-interaction account takeover (admin accounts included)
Fixed VersionKeycloak 26.7.2 (upstream) / RHBK 26.4.15-1, 26.6.6-1