### CVE-2026-18963 attempt role=fixed num=1 step1 forgot-password URL: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?client_id=account&tab_id=C5nzIDp41LQ&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step2 choose-user form action: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?session_code=4LW2oD5uI8u9q3mBLBwGeLF_w5V6fxW7hG_P_Qki4Ok&execution=97238d1c-c9bd-4951-b8df-561d7eb02e65&client_id=account&tab_id=C5nzIDp41LQ&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step3 tryAnotherWay -> selector screen markers: 1 step3 selector form action: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?session_code=rh_j8PLdx20rkTyinj9YHoeVzRD_FxjLB9QL9j6LiGw&execution=97238d1c-c9bd-4951-b8df-561d7eb02e65&client_id=account&tab_id=C5nzIDp41LQ&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step4 username=victim -> email-sent page markers: 1 step4 smtp action-token links captured: before=4 after=6 step4 NOTE: the action-token link went to victim@cvetest.local only; the attacker never sees it step5 GET refresh -> selector markers=0 email-sent markers=1 step5 FIXED-BEHAVIOR: selector screen NOT re-rendered; flow still waits for the email fixed verify: old-password token HTTP 200 (want 200), new-password token HTTP 400 (want !=200) RESULT: BLOCKED (fix confirmed)