### CVE-2026-18963 attempt role=fixed num=2 step1 forgot-password URL: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?client_id=account&tab_id=ZJRYt4miFBs&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step2 choose-user form action: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?session_code=y7g6r-iwUpkzOWfNg-WAMH8MF6ozoCwM9pOJvRwGe6c&execution=97238d1c-c9bd-4951-b8df-561d7eb02e65&client_id=account&tab_id=ZJRYt4miFBs&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step3 tryAnotherWay -> selector screen markers: 1 step3 selector form action: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?session_code=fhW4yIOktBP8iEMGfvTU-N4MmA7tDgx2PhwdI2HK96g&execution=97238d1c-c9bd-4951-b8df-561d7eb02e65&client_id=account&tab_id=ZJRYt4miFBs&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step4 username=victim -> email-sent page markers: 1 step4 smtp action-token links captured: before=8 after=10 step4 NOTE: the action-token link went to victim@cvetest.local only; the attacker never sees it step5 GET refresh -> selector markers=0 email-sent markers=1 step5 FIXED-BEHAVIOR: selector screen NOT re-rendered; flow still waits for the email fixed verify: old-password token HTTP 200 (want 200), new-password token HTTP 400 (want !=200) RESULT: BLOCKED (fix confirmed)