
Nuclei template to discover exposed Keycloak reset-credentials endpoints across multiple paths, aiding validation of CVE-2026-18963 exposure.
Nuclei template to discover exposed Keycloak reset-credentials endpoints across multiple proxy prefixes, context paths, realm names, and path variations.
This template helps identify reachable password reset flows that may be relevant during validation of environments affected by:
According to the public Keycloak issue, the vulnerability allows an unauthenticated attacker to force the password reset process for a user without requiring the expected email verification link, potentially leading to full account takeover.
Reference:
nuclei -t reset-path-finder.yaml -u https://target.example