Sploitus

Exploit for CVE-2026-18963 CVE-2026-18963 CVE-2026-39816 CVE-2026-5006 CVE-2026-7474

githubexploit · 2026-08-31

Exploit Code

README64 lines
## https://sploitus.com/exploit?id=6BA66D15-4D58-52B5-99B1-5E48A1880BB9
# 0day-Exploits

Vulnerability research I have done on four widely deployed platform services: Keycloak,
Apache NiFi, HashiCorp Vault and HashiCorp Nomad. For each finding this repo carries the
write-once artifacts I actually use, a Metasploit module where it made sense, a standalone
Python proof of concept, and a small Docker lab that stands up only the vulnerable service
so anyone can reproduce the bug without taking my word for it.

Nothing here targets a live environment. The labs are throwaway containers on your own host.

## Findings

| CVE | Component | Class | Affected | Metasploit | PoC | Lab |
|-----|-----------|-------|----------|:---------:|:---:|:---:|
| CVE-2026-18963 | Keycloak | Reset-credentials sticky-selector account takeover | < 26.7.2 | yes | yes | yes |
| CVE-2026-39816 | Apache NiFi | Tinkerpop / ExecuteGraphQuery Groovy RCE past the execute-code gate | 2.0.0-M1 .. 2.8.0 | yes | yes | yes |
| CVE-2026-5006 | HashiCorp Vault | Templated-policy metadata slash injection (HCSEC-2026-32) | <= 2.0.3 | yes | yes | yes |
| CVE-2026-7474 | HashiCorp Nomad | Dynamic host-volume `plugin_id` path traversal to root (HCSEC-2026-15) | <= 2.0.0 | | yes | yes |

## Layout

```
metasploit-custom-modules/   Metasploit modules + module docs, in the normal framework tree
exploits/                    one self-contained Python PoC per CVE
docker-lab/                  one throwaway Docker lab per CVE, spins up only the vulnerable service
```

Each of those three has its own README with the details. Short version:

- **metasploit-custom-modules/** drops straight into a framework checkout (or your
  `~/.msf4`). Three modules: the Keycloak takeover, the Vault metadata slash injection, and
  the NiFi RCE.
- **exploits/** is four dependency-light Python scripts, one per CVE. They run against the
  matching lab with no edits.
- **docker-lab/** is four independent labs. Each pins the last vulnerable release, wires up
  whatever the bug actually needs (real OIDC for NiFi, a real Docker engine for Nomad), and
  nothing more. No flags, no chained scenario, just the bug.

## Reproducing a finding

Pick a CVE, bring its lab up, fire the PoC. For example, Keycloak:

```
cd docker-lab/keycloak-cve-2026-18963
docker compose up -d
cd ../..
python3 exploits/kc_ato_18963.py \
    --base http://127.0.0.1:8080 --realm larkspur \
    --victim j.okonkwo --newpass Chang3d-by-attacker!
```

The other three follow the same pattern. Read the per-lab README first, a couple of them
need `--build` and a minute to provision.

## Disclosure

All four were reported to the respective vendors and are fixed in the versions noted above.
Everything published here runs against the deliberately outdated images in `docker-lab/`.
Point it at anything you do not own and that is on you.

## License

MIT. See [LICENSE](LICENSE).