## https://sploitus.com/exploit?id=6BA66D15-4D58-52B5-99B1-5E48A1880BB9
# 0day-Exploits
Vulnerability research I have done on four widely deployed platform services: Keycloak,
Apache NiFi, HashiCorp Vault and HashiCorp Nomad. For each finding this repo carries the
write-once artifacts I actually use, a Metasploit module where it made sense, a standalone
Python proof of concept, and a small Docker lab that stands up only the vulnerable service
so anyone can reproduce the bug without taking my word for it.
Nothing here targets a live environment. The labs are throwaway containers on your own host.
## Findings
| CVE | Component | Class | Affected | Metasploit | PoC | Lab |
|-----|-----------|-------|----------|:---------:|:---:|:---:|
| CVE-2026-18963 | Keycloak | Reset-credentials sticky-selector account takeover | < 26.7.2 | yes | yes | yes |
| CVE-2026-39816 | Apache NiFi | Tinkerpop / ExecuteGraphQuery Groovy RCE past the execute-code gate | 2.0.0-M1 .. 2.8.0 | yes | yes | yes |
| CVE-2026-5006 | HashiCorp Vault | Templated-policy metadata slash injection (HCSEC-2026-32) | <= 2.0.3 | yes | yes | yes |
| CVE-2026-7474 | HashiCorp Nomad | Dynamic host-volume `plugin_id` path traversal to root (HCSEC-2026-15) | <= 2.0.0 | | yes | yes |
## Layout
```
metasploit-custom-modules/ Metasploit modules + module docs, in the normal framework tree
exploits/ one self-contained Python PoC per CVE
docker-lab/ one throwaway Docker lab per CVE, spins up only the vulnerable service
```
Each of those three has its own README with the details. Short version:
- **metasploit-custom-modules/** drops straight into a framework checkout (or your
`~/.msf4`). Three modules: the Keycloak takeover, the Vault metadata slash injection, and
the NiFi RCE.
- **exploits/** is four dependency-light Python scripts, one per CVE. They run against the
matching lab with no edits.
- **docker-lab/** is four independent labs. Each pins the last vulnerable release, wires up
whatever the bug actually needs (real OIDC for NiFi, a real Docker engine for Nomad), and
nothing more. No flags, no chained scenario, just the bug.
## Reproducing a finding
Pick a CVE, bring its lab up, fire the PoC. For example, Keycloak:
```
cd docker-lab/keycloak-cve-2026-18963
docker compose up -d
cd ../..
python3 exploits/kc_ato_18963.py \
--base http://127.0.0.1:8080 --realm larkspur \
--victim j.okonkwo --newpass Chang3d-by-attacker!
```
The other three follow the same pattern. Read the per-lab README first, a couple of them
need `--build` and a minute to provision.
## Disclosure
All four were reported to the respective vendors and are fixed in the versions noted above.
Everything published here runs against the deliberately outdated images in `docker-lab/`.
Point it at anything you do not own and that is on you.
## License
MIT. See [LICENSE](LICENSE).