The KeySniper author describes KeySniper as a scanner for authorized checks of CVE-2026-18963. The author writes that the flaw lets an unauthenticated caller trigger a password reset for a known username and reach the UPDATE_PASSWORD page without following the link in the email.
According to the author, KeySniper’s default mode detects the issue without changing a password. According to the author, –takeover 1 changes the target account password.
Claim check:
- The KeySniper author describes KeySniper as a scanner for authorized checks of CVE-2026-18963. (confirmed by the publication itself: evidence; «KeySniper is a production-oriented scanner for in-scope bug bounty and authorized assessments»)
- The author writes that the flaw lets an unauthenticated caller trigger a password reset for a known username and reach the UPDATE_PASSWORD page without following the link in the email. (confirmed by the publication itself: evidence; «Result: an unauthenticated caller can force the password-reset flow for a known username and land on UPDATE_PASSWORD without clicking the email link.»)
- The author writes that KeySniper’s default mode detects the issue without changing a password. (confirmed by the publication itself: evidence; «Default mode is detect ( –takeover 0 ).»)
- The author writes that –takeover 1 changes the target account password. (confirmed by the publication itself: evidence; «–takeover 1 changes the account password on the target.»)
Primary sources:
score 80.1 · kind incident · revision 1 · stories st-87paza