
Metasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp Vault (CVE-2026-5006), HashiCorp Nomad (CVE-2026-7474).
Vulnerability research I have done on four widely deployed platform services: Keycloak, Apache NiFi, HashiCorp Vault and HashiCorp Nomad. For each finding this repo carries the write-once artifacts I actually use, a Metasploit module where it made sense, a standalone Python proof of concept, and a small Docker lab that stands up only the vulnerable service so anyone can reproduce the bug without taking my word for it.
Nothing here targets a live environment. The labs are throwaway containers on your own host.
| CVE | Component | Class | Affected | Metasploit | PoC | Lab |
|---|---|---|---|---|---|---|
| CVE-2026-18963 | Keycloak | Reset-credentials sticky-selector account takeover | < 26.7.2 | yes | yes | yes |
| CVE-2026-39816 | Apache NiFi | Tinkerpop / ExecuteGraphQuery Groovy RCE past the execute-code gate | 2.0.0-M1 .. 2.8.0 | yes | yes | yes |
| CVE-2026-5006 | HashiCorp Vault | Templated-policy metadata slash injection (HCSEC-2026-32) | <= 2.0.3 | yes | yes | yes |
| CVE-2026-7474 | HashiCorp Nomad | Dynamic host-volume plugin_id path traversal to root (HCSEC-2026-15) | <= 2.0.0 | yes | yes |
metasploit-custom-modules/ Metasploit modules + module docs, in the normal framework tree
exploits/ one self-contained Python PoC per CVE
docker-lab/ one throwaway Docker lab per CVE, spins up only the vulnerable service
Each of those three has its own README with the details. Short version:
~/.msf4). Three modules: the Keycloak takeover, the Vault metadata slash injection, and
the NiFi RCE.Pick a CVE, bring its lab up, fire the PoC. For example, Keycloak:
cd docker-lab/keycloak-cve-2026-18963
docker compose up -d
cd ../..
python3 exploits/kc_ato_18963.py \
--base http://127.0.0.1:8080 --realm larkspur \
--victim j.okonkwo --newpass Chang3d-by-attacker!
The other three follow the same pattern. Read the per-lab README first, a couple of them
need --build and a minute to provision.
All four were reported to the respective vendors and are fixed in the versions noted above.
Everything published here runs against the deliberately outdated images in docker-lab/.
Point it at anything you do not own and that is on you.
MIT. See LICENSE.