discovered 25 Aug 2026
CVE-2026-18963-Exploit
→ View on GitHubThe CVE-2026-18963-Exploit tool allows users to test for a critical security vulnerability in Keycloak versions 26.0.0 to 26.7.1, which enables unauthenticated attackers to reset passwords without victim interaction. It features a safe detection mode that requires only the base URL and realm settings, avoiding any impact on the target system. Additionally, it includes a lab environment for practical demonstration of the exploit and its remediation.