
👾 CVE-2026-60206 - Oracle WebLogic SAML Auth Bypass Exploit Framework ⚡Bash & Python versions. Features: --detect safe check, --exploit combo/unsigned/xsw/nameid/all, --shodan integration, --tor support, mass scanning, JSON/CSV/JSONL output, cookie validation. 🛡️ CVSS 9.9 Critical - Use Ethically, Stay Legal. 🔒

Exploit Framework & Mass Scanner
For authorized security testing only.
This tool is provided for educational and authorized penetration testing purposes only.
The authors and contributors are not responsible for any misuse or damage caused by this software. Users are solely responsible for ensuring they have explicit written permission from the target owner before testing. Unauthorized access to computer systems is illegal under the Computer Fraud and Abuse Act (CFAA) and similar laws worldwide.
By using this software, you agree to:
⚠️ WARNING: This vulnerability is actively exploited in the wild. Unauthorized use may result in severe legal consequences.
CVE-2026-60206 is a critical unauthenticated authentication bypass vulnerability in Oracle WebLogic Server's SAML (Security Assertion Markup Language) implementation. It allows remote attackers to bypass SAML authentication and gain administrative access to the WebLogic console without valid credentials.
SAML Injection: The vulnerability stems from improper validation of SAML assertions. Attackers can craft malicious SAML responses that bypass authentication checks.
Signature Bypass: The vulnerability allows bypassing XML signature validation through XML Signature Wrapping (XSW) attacks, where attackers wrap malicious assertions with legitimate signatures.
NameID Manipulation: Attackers can inject comments or manipulate the NameID field to impersonate privileged users.
Admin Access: Successful exploitation grants the attacker administrative access to the WebLogic Server console with full control.
| Attribute | Value |
|---|---|
| 📅 Discovered | July 2026 (Oracle CPU) |
| ⚠️ CVSS Score | 9.9 (CRITICAL) |
| 📋 CISA KEV | Added July 21, 2026 |
| 🎯 Affected Products | Oracle WebLogic Server (Fusion Middleware) |
| 🔄 Fixed Versions | Oracle CPU July 2026 |
| 🔓 Authentication | Not required (Pre-Auth) |
| 🌍 Active Exploitation | Confirmed in the wild (July 2026) |
The full educational multi-exploit chains multiple SAML attack vectors to achieve authentication bypass, with advanced features for mass scanning, cookie, and administrative access.
| Feature | Description |
|---|---|
| 🚀 Multi-Vector Exploit | 7 attack vectors: unsigned, xsw_v1-4, nameid, combo |
| 💻 Mass Scanning | Concurrent scanning with thread pool (Python) / FIFO (Bash) |
| 🔐 Cookie Theft | Steals JSESSIONID for session hijacking |
| 👑 Admin Console Access | Full administrative access to WebLogic console |
| 📁 Version Detection | Detects WebLogic versions and vulnerability status |
| 🌐 Batch Scanning | Mass exploit multiple targets with threading |
| 🎯 Safe Detection | Optional --detect flag for non‑intrusive vulnerability verification |
| 🧩 Shodan Integration | Load targets directly from Shodan search |
| 🔍 Tor Support | Anonymize scanning with Tor proxy |
| 📊 Multiple Output Formats | JSON, CSV, JSONL streaming output |
| 🪟 Cross‑Platform | Supports Linux, macOS, BSD, Alpine, WSL |
| 🔒 Thread‑Safe | Uses locking mechanisms for concurrent operations |
| 📋 Auto Session Save | Saves successful cookies for later use |
| ⚙️ WAF Bypass | User-Agent rotation and random delays |
| Vector | Description |
|---|---|
unsigned | Unauthenticated SAML assertion without signature |
xsw_v1 | XML Signature Wrapping - Multiple assertions |
xsw_v2 | XSW - Enveloped signature bypass |
xsw_v3 | XSW - Namespace manipulation |
xsw_v4 | XSW - Multiple assertion injection |
nameid | NameID comment injection |
combo | Combined attack (unsigned + XSW + NameID) |
--detect)The safe verifier performs non‑intrusive vulnerability detection without executing harmful payloads or making system changes.
| Feature | Description |
|---|---|
| 🔍 WebLogic Detection | Identifies WebLogic instances via LoginForm.jsp |
| 📊 Version Detection | Detects specific WebLogic versions and patch levels |
| 🧪 SAML Endpoint Discovery | Tests for SAML ACS endpoints |
| 🔒 Non‑Intrusive | Only identifies vulnerable versions |
| 📋 JSON/CSV Output | Export results for reporting |
| 🔄 Mass Scanning | Scan multiple targets with threading support |
curl (for Bash version)pip (for requests library, Python version)# Python version
pip install requests urllib3
# Optional: Shodan support
pip install shodan
# Bash version: curl only (no additional dependencies)
[!NOTE] The Bash version works with
curlonly and has no external dependencies. The Python version requiresrequestsandurllib3(optional:shodanfor Shodan integration).
exploit.py)# Single target exploit (combo mode)
python exploit.py -u https://192.168.1.100:7002 --exploit --user admin
# Exploit with all attack vectors
python exploit.py -u https://192.168.1.100:7002 --mode all --exploit -v
# Mass scanning from file (50 threads)
python exploit.py -l targets.txt --exploit -t 50 -o results.json
# Safe detection only (non-intrusive)
python exploit.py -l targets.txt --detect -o scan_results.csv
# Shodan integration
export SHODAN_API_KEY="your_api_key"
python exploit.py --shodan --shodan-query "WebLogic Server port:7002" --exploit
# Tor anonymized scanning
python exploit.py -l targets.txt --exploit --tor -t 20
# Proxy support
python exploit.py -u https://192.168.1.100:7002 --exploit --proxy http://127.0.0.1:8080
# Streaming JSONL output (memory efficient for large scans)
python exploit.py -l targets.txt --exploit -o results.jsonl
# Quiet mode (minimal output)
python exploit.py -l targets.txt --exploit -q -o results.json