CVE-2026-60206
CRITICALOracle WebLogic Server 12.2.1.4.0/14.1.1.0.0/14.1.2.0.0/15.1.1.0.0 - Authenticated Remote Code Execution via SAML
Title source: llmExploitation Summary
EIP tracks 4 public exploits for CVE-2026-60206. PoCs published by tc4dy, Debajyoti0-0, imbas007.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-60206, an Oracle WebLogic SAML Authentication Bypass vulnerability. The exploit crafts malicious SAML assertions (unsigned and XML Signature Wrapping variants) to bypass authentication and gain unauthorized access to the WebLogic admin console.
Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SAML to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Exploits (4)
This repository contains a functional exploit for CVE-2026-60206, an Oracle WebLogic SAML Authentication Bypass vulnerability. The exploit crafts malicious SAML assertions (unsigned and XML Signature Wrapping variants) to bypass authentication and gain unauthorized access to the WebLogic admin console.
This repository provides a functional proof-of-concept exploit for CVE-2026-60206, a critical SAML authentication bypass vulnerability in Oracle WebLogic Server. The exploit leverages multiple attack vectors, including XML Signature Wrapping (XSW), unsigned assertion injection, and NameID manipulation, to forge SAML assertions and gain administrative access without authentication.
This repository contains a functional proof-of-concept exploit for CVE-2026-60206, an authentication bypass vulnerability in Oracle WebLogic Server via SAML manipulation. The exploit implements multiple attack vectors including XML Signature Wrapping (XSW), unsigned assertion injection, and NameID manipulation to bypass authentication controls.
This repository contains a functional proof-of-concept exploit for CVE-2026-60206, a critical SAML authentication vulnerability in Oracle WebLogic Server. The exploit generates a malicious SAML response to bypass authentication and escalate privileges to administrative level without proper validation.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H