Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/infernosalex/cve-2026-33439-python-poc
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRemote Access Tool
GitHubinfernosalex/cve-2026-33439-python-poc

CVE-2026-33439-Python-PoC

Python PoC for CVE-2026-33439, an OpenAM pre-authentication RCE via jato.clientSession deserialization

View Repository
45021 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-33439 Python PoC

Standalone Python proof of concept for the OpenAM pre-authentication remote code execution vulnerability in jato.clientSession deserialization.

The embedded shaded Click/Xalan gadget reads a shell command from the cmd HTTP header and returns its output in the HTTP response. No external Python packages, Java runtime, or JAR files are required.

Usage

python3 exploit.py \
  --url https://target.example/openam/ui/PWResetUserValidation \
  'id'

Optional arguments:

--timeout SECONDS     Request timeout (default: 15)
--proxy URL           HTTP proxy, for example http://127.0.0.1:8080
--verify-tls          Enable TLS certificate verification

References

  • OpenAM security advisory GHSA-2cqq-rpvq-g5qj
  • CVE-2026-33439

Use only against systems you own or are explicitly authorized to test.

Download Tool