Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-1529 — Keycloak: Unauthorized organization registration via improper invitation token validation | Kitploit
Tools/GitHubGitHub/0x240x23elu/cve-2026-1529
Authentication & AuthorizationPayload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration Testing
GitHub0x240x23elu/cve-2026-1529

CVE-2026-1529

Keycloak: Unauthorized organization registration via improper invitation token validation

View Repository
62177 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-1529 Keycloak Exploit Tool

Python Version License Status

CVE-2026-1529: Keycloak - Unauthorized organization registration via improper invitation token validation

⚠️ WARNING: This tool is for educational and authorized security testing purposes only. Unauthorized access to computer systems is illegal.

📋 Table of Contents

  • Overview
  • Features
  • Prerequisites
  • Installation
  • Usage
  • Configuration
  • How It Works
  • Output
  • Troubleshooting
  • Legal Disclaimer
  • Contributing
  • Credits

🎯 Overview

This tool demonstrates a critical vulnerability in Keycloak (CVE-2026-1529) that allows unauthorized organization registration through improper JWT invitation token validation. The exploit manipulates invitation tokens to gain unauthorized access to Keycloak instances.

Vulnerability Details:

  • CVE ID: CVE-2026-1529
  • Severity: Critical
  • Attack Vector: Network
  • Attack Complexity: Low
  • Affected: Keycloak instances with organization invitation feature

✨ Features

  • ✅ Automatic vulnerability detection
  • ✅ JWT token manipulation
  • ✅ Automated user registration
  • ✅ Login verification
  • ✅ Detailed exploit reports
  • ✅ Configurable parameters
  • ✅ Debug logging support
  • ✅ Multi-retry HTTP client

📦 Prerequisites

  • Python 3.7 or higher
  • pip (Python package manager)
  • Virtual environment (recommended)
  • Target Keycloak instance (authorized testing only)

🚀 Installation

Method 1: Clone Repository

# Clone the repository
git clone https://github.com/yourusername/cve-2026-1529-exploit.git
cd cve-2026-1529-exploit

# Create virtual environment
python3 -m venv venv
source venv/bin/activate  # On Windows: venv\Scripts\activate

# Install dependencies
pip install -r requirements.txt

Method 2: Manual Setup

# Create directory structure
mkdir -p keycloak-exploit/{utils,config,logs,output/reports}
cd keycloak-exploit

# Download files from releases or copy manually
# Then install dependencies
pip install requests urllib3 PyJWT

File Structure

keycloak-exploit/
├── keycloak-exploit.py           # Main exploit script
├── requirements.txt              # Python dependencies
├── README.md                     # This file
├── config/
│   └── default_config.json       # Configuration file
├── utils/
│   ├── __init__.py              # Package initializer
│   ├── http_utils.py            # HTTP client utilities
│   ├── jwt_utils.py             # JWT manipulation
│   └── crypto_utils.py          # Crypto utilities
├── logs/                         # Auto-generated logs
└── output/
    └── reports/                  # Exploit reports

💻 Usage

Basic Usage

python3 keycloak-exploit.py https://target-keycloak.com

Advanced Options

# With custom invitation token
python3 keycloak-exploit.py -t eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9... https://target.com

# With custom organization ID
python3 keycloak-exploit.py -o custom_org_id https://target.com

# With custom configuration file
python3 keycloak-exploit.py -c /path/to/config.json https://target.com

# Enable debug logging
python3 keycloak-exploit.py -d https://target.com

# Show help
python3 keycloak-exploit.py -h

# Show version
python3 keycloak-exploit.py -v

Command Line Arguments

ArgumentShortDescription
target-Target Keycloak URL (required)
--token-tCustom invitation token
--org-id-oCustom organization ID
--config-cPath to configuration file
--debug-dEnable debug logging
--version-vShow version information
--help-hShow help message

⚙️ Configuration

Edit config/default_config.json to customize exploit parameters:

{
    "exploit": {
        "default_username": "admin_user_2026",
        "default_password": "KeycloakCVE2026!",
        "default_email": "[email protected]",
        "timeout": 30,
        "max_retries": 3
    },
    "jwt": {
        "algorithm": "HS256",
        "secret_key": "keycloak-cve-2026-1529-exploit",
        "token_expiry": 3600
    },
    "target": {
        "endpoints": {
            "realms": "/realms",
            "organizations": "/organizations",
            "register": "/register",
            "login": "/login"
        }
    },
    "output": {
        "log_level": "INFO",
        "save_reports": true,
        "report_format": "txt"
    }
}

Configuration Options

SectionParameterDescriptionDefault
exploitdefault_usernameUsername for registrationadmin_user_2026
exploitdefault_passwordPassword for registrationKeycloakCVE2026!
exploitdefault_emailEmail for registration[email protected]
exploittimeoutHTTP request timeout (seconds)30
exploitmax_retriesMax HTTP retries3
jwtalgorithmJWT signing algorithmHS256
jwtsecret_keyJWT secret keyCustom
jwttoken_expiryToken expiry (seconds)3600

🔧 How It Works

The exploit works in the following steps:

  1. Vulnerability Check

    • Connects to target Keycloak instance
    • Detects Keycloak version
    • Tests organization endpoints
  2. Token Generation/Manipulation

    • Generates or accepts invitation token
    • Decodes JWT token
    • Manipulates organization ID in payload
    • Re-signs token with known key
  3. User Registration

    • Submits registration with manipulated token
    • Bypasses organization validation
    • Creates unauthorized user account
  4. Login Verification

    • Tests login with created credentials
    • Generates access token
    • Provides login URL
  5. Report Generation

    • Creates detailed exploit report
    • Saves to output/reports/
    • Includes all technical details

Attack Flow Diagram

┌─────────────────┐
│  Target Check   │
└────────┬────────┘
         │
         ▼
┌─────────────────┐
│  Token Gen/Get  │
└────────┬────────┘
         │
         ▼
┌─────────────────┐
│ Token Manipulate│
└────────┬────────┘
         │
         ▼
┌─────────────────┐
│ User Register   │
└────────┬────────┘
         │
         ▼
┌─────────────────┐
│  Login Test     │
└────────┬────────┘
         │
         ▼
┌─────────────────┐
│  Report Gen     │
└─────────────────┘

📊 Output

Successful Exploit Output

============================================================
CVE-2026-1529 EXPLOIT RESULTS
============================================================
✓ Target is vulnerable to CVE-2026-1529

🎯 EXPLOIT SUCCESSFUL!
Username: admin_user_2026
Password: KeycloakCVE2026!
Email: [email protected]
Login Link: https://target.com/realms/master/account

📄 Report saved to: output/reports/exploit_report_20260211_050507.txt

🔐 Use the provided credentials to access the Keycloak instance!
⚠️  This demonstrates unauthorized access due to CVE-2026-1529

============================================================
by f3ds cr3w est, 2002
============================================================

Generated Report

A detailed report is saved to output/reports/ containing:

  • Target information
  • Exploit results for each step
  • Created user credentials
  • Login link
  • Original and manipulated tokens
  • Technical details
  • CVE information
  • Security advisory

Log Files

Logs are saved to logs/ directory with detailed execution information.

🐛 Troubleshooting

Common Issues

1. ModuleNotFoundError: No module named 'utils'

Download Tool