Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-60206-PoC-Exploit — 👾 CVE-2026-60206 - Oracle WebLogic SAML Auth Bypass Exploit Framework ⚡Bash & Python versions. Features: --detect safe check, --exploit combo/unsigned/xsw/nameid/all, --shodan integration, --tor support, mass scanning, JSON/CSV/JSONL output, cookie validation. 🛡️ CVSS 9.9 Critical - Use Ethically, Stay Legal. 🔒 | Kitploit
Tools/GitHubGitHub/tc4dy/cve-2026-60206-poc-exploit
Authentication & AuthorizationExploit FrameworksPayload GenerationVulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPost-Exploitation

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

About

WAF Bypass
Penetration Testing
Red Teaming
GitHubtc4dy/cve-2026-60206-poc-exploit

CVE-2026-60206-PoC-Exploit

View Repository
42162 months agoNot yet reviewed

👾 CVE-2026-60206 - Oracle WebLogic SAML Auth Bypass Exploit Framework ⚡Bash & Python versions. Features: --detect safe check, --exploit combo/unsigned/xsw/nameid/all, --shodan integration, --tor support, mass scanning, JSON/CSV/JSONL output, cookie validation. 🛡️ CVSS 9.9 Critical - Use Ethically, Stay Legal. 🔒

Share

CVE-2026-60206

CVE-2026-60206 - Oracle WebLogic SAML Auth Bypass Exploit Framework-Toolkit

CVE-2026-60206 CVSS 9.9 CISA KEV Python 3.6+

Pre-Auth Bypass SAML Injection Admin Access Cross-Platform

Oracle WebLogic Server — SAML Authentication Bypass → Admin Takeover

Exploit Framework & Mass Scanner
For authorized security testing only.


⚖️ Legal Disclaimer & Responsible Use

This tool is provided for educational and authorized penetration testing purposes only.

The authors and contributors are not responsible for any misuse or damage caused by this software. Users are solely responsible for ensuring they have explicit written permission from the target owner before testing. Unauthorized access to computer systems is illegal under the Computer Fraud and Abuse Act (CFAA) and similar laws worldwide.

By using this software, you agree to:

  • Use it only on systems you own or have explicit permission to test.
  • Comply with all applicable local, state, and federal laws.
  • Not use it for any malicious, destructive, or illegal activities.

⚠️ WARNING: This vulnerability is actively exploited in the wild. Unauthorized use may result in severe legal consequences.


[+!] Vulnerability Overview

CVE-2026-60206 is a critical unauthenticated authentication bypass vulnerability in Oracle WebLogic Server's SAML (Security Assertion Markup Language) implementation. It allows remote attackers to bypass SAML authentication and gain administrative access to the WebLogic console without valid credentials.

How it works:

  1. SAML Injection: The vulnerability stems from improper validation of SAML assertions. Attackers can craft malicious SAML responses that bypass authentication checks.

  2. Signature Bypass: The vulnerability allows bypassing XML signature validation through XML Signature Wrapping (XSW) attacks, where attackers wrap malicious assertions with legitimate signatures.

  3. NameID Manipulation: Attackers can inject comments or manipulate the NameID field to impersonate privileged users.

  4. Admin Access: Successful exploitation grants the attacker administrative access to the WebLogic Server console with full control.

Key Facts:

AttributeValue
📅 DiscoveredJuly 2026 (Oracle CPU)
⚠️ CVSS Score9.9 (CRITICAL)
📋 CISA KEVAdded July 21, 2026
🎯 Affected ProductsOracle WebLogic Server (Fusion Middleware)
🔄 Fixed VersionsOracle CPU July 2026
🔓 AuthenticationNot required (Pre-Auth)
🌍 Active ExploitationConfirmed in the wild (July 2026)

🛠️ Exploit Framework

The full educational multi-exploit chains multiple SAML attack vectors to achieve authentication bypass, with advanced features for mass scanning, cookie, and administrative access.

✨ Features

FeatureDescription
🚀 Multi-Vector Exploit7 attack vectors: unsigned, xsw_v1-4, nameid, combo
💻 Mass ScanningConcurrent scanning with thread pool (Python) / FIFO (Bash)
🔐 Cookie TheftSteals JSESSIONID for session hijacking
👑 Admin Console AccessFull administrative access to WebLogic console
📁 Version DetectionDetects WebLogic versions and vulnerability status
🌐 Batch ScanningMass exploit multiple targets with threading
🎯 Safe DetectionOptional --detect flag for non‑intrusive vulnerability verification
🧩 Shodan IntegrationLoad targets directly from Shodan search
🔍 Tor SupportAnonymize scanning with Tor proxy
📊 Multiple Output FormatsJSON, CSV, JSONL streaming output
🪟 Cross‑PlatformSupports Linux, macOS, BSD, Alpine, WSL
🔒 Thread‑SafeUses locking mechanisms for concurrent operations
📋 Auto Session SaveSaves successful cookies for later use
⚙️ WAF BypassUser-Agent rotation and random delays

Attack Vectors

VectorDescription
unsignedUnauthenticated SAML assertion without signature
xsw_v1XML Signature Wrapping - Multiple assertions
xsw_v2XSW - Enveloped signature bypass
xsw_v3XSW - Namespace manipulation
xsw_v4XSW - Multiple assertion injection
nameidNameID comment injection
comboCombined attack (unsigned + XSW + NameID)

🕵️ Safe Verifier (--detect)

The safe verifier performs non‑intrusive vulnerability detection without executing harmful payloads or making system changes.

✨ Features

FeatureDescription
🔍 WebLogic DetectionIdentifies WebLogic instances via LoginForm.jsp
📊 Version DetectionDetects specific WebLogic versions and patch levels
🧪 SAML Endpoint DiscoveryTests for SAML ACS endpoints
🔒 Non‑IntrusiveOnly identifies vulnerable versions
📋 JSON/CSV OutputExport results for reporting
🔄 Mass ScanningScan multiple targets with threading support

📦 Installation & Requirements

Prerequisites

  • Python 3.6+ or Bash 3.2+
  • curl (for Bash version)
  • pip (for requests library, Python version)

Install Dependencies

# Python version
pip install requests urllib3

# Optional: Shodan support
pip install shodan

# Bash version: curl only (no additional dependencies)

[!NOTE] The Bash version works with curl only and has no external dependencies. The Python version requires requests and urllib3 (optional: shodan for Shodan integration).


🚀 Usage Examples

[1] Python Exploit Framework (exploit.py)

# Single target exploit (combo mode)
python exploit.py -u https://192.168.1.100:7002 --exploit --user admin

# Exploit with all attack vectors
python exploit.py -u https://192.168.1.100:7002 --mode all --exploit -v

# Mass scanning from file (50 threads)
python exploit.py -l targets.txt --exploit -t 50 -o results.json

# Safe detection only (non-intrusive)
python exploit.py -l targets.txt --detect -o scan_results.csv

# Shodan integration
export SHODAN_API_KEY="your_api_key"
python exploit.py --shodan --shodan-query "WebLogic Server port:7002" --exploit

# Tor anonymized scanning
python exploit.py -l targets.txt --exploit --tor -t 20

# Proxy support
python exploit.py -u https://192.168.1.100:7002 --exploit --proxy http://127.0.0.1:8080

# Streaming JSONL output (memory efficient for large scans)
python exploit.py -l targets.txt --exploit -o results.jsonl

# Quiet mode (minimal output)
python exploit.py -l targets.txt --exploit -q -o results.json
Download Tool