CVE-2026-60206

CRITICAL

Oracle WebLogic Server 12.2.1.4.0/14.1.1.0.0/14.1.2.0.0/15.1.1.0.0 - Authenticated Remote Code Execution via SAML

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2026-60206. PoCs published by tc4dy, Debajyoti0-0, imbas007.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-60206, an Oracle WebLogic SAML Authentication Bypass vulnerability. The exploit crafts malicious SAML assertions (unsigned and XML Signature Wrapping variants) to bypass authentication and gain unauthorized access to the WebLogic admin console.

Description

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SAML to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Exploits (4)

github WORKING POC 3 stars
by tc4dy · shellpoc
https://github.com/tc4dy/CVE-2026-60206-PoC-Exploit

This repository contains a functional exploit for CVE-2026-60206, an Oracle WebLogic SAML Authentication Bypass vulnerability. The exploit crafts malicious SAML assertions (unsigned and XML Signature Wrapping variants) to bypass authentication and gain unauthorized access to the WebLogic admin console.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
No auth needed
Prerequisites: Target must have SAML authentication enabled · Accessible SAML endpoint (e.g., /saml2/sp/acs)
mistral-large-3 · analyzed Jul 25, 2026 Full analysis →
github WORKING POC
by Debajyoti0-0 · pythonpoc
https://github.com/Debajyoti0-0/CVE-2026-60206

This repository provides a functional proof-of-concept exploit for CVE-2026-60206, a critical SAML authentication bypass vulnerability in Oracle WebLogic Server. The exploit leverages multiple attack vectors, including XML Signature Wrapping (XSW), unsigned assertion injection, and NameID manipulation, to forge SAML assertions and gain administrative access without authentication.

Classification
Working Poc 98%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
No auth needed
Prerequisites: Network access to the WebLogic Server SAML endpoint · Knowledge of the target's SAML ACS (Assertion Consumer Service) URL · Optional: Valid SAML metadata or captured SAML response for replay attacks
mistral-large-3 · analyzed Jul 25, 2026 Full analysis →
github WORKING POC
by imbas007 · pythonpoc
https://github.com/imbas007/POC-CVE-2026-60206

This repository contains a functional proof-of-concept exploit for CVE-2026-60206, an authentication bypass vulnerability in Oracle WebLogic Server via SAML manipulation. The exploit implements multiple attack vectors including XML Signature Wrapping (XSW), unsigned assertion injection, and NameID manipulation to bypass authentication controls.

Classification
Working Poc 98%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
No auth needed
Prerequisites: Network access to WebLogic Server SAML endpoint · Target must have SAML authentication configured (though exploit attempts to detect this)
mistral-large-3 · analyzed Jul 24, 2026 Full analysis →
github WORKING POC
by 0xBlackash · pythonpoc
https://github.com/0xBlackash/CVE-2026-60206

This repository contains a functional proof-of-concept exploit for CVE-2026-60206, a critical SAML authentication vulnerability in Oracle WebLogic Server. The exploit generates a malicious SAML response to bypass authentication and escalate privileges to administrative level without proper validation.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Auth required
Prerequisites: Network access to the WebLogic SAML endpoint · Low-privilege authenticated access (e.g., valid user credentials)
mistral-large-3 · analyzed Jul 24, 2026 Full analysis →

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory
Oracle Advisory
https://www.oracle.com/security-alerts/cpujul2026.html

Scores

CVSS v3 9.9
EPSS 0.0045
EPSS Percentile 36.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-306
Status published
Products (4)
Oracle Corporation/Oracle WebLogic Server 12.2.1.4.0
Oracle Corporation/Oracle WebLogic Server 14.1.1.0.0
Oracle Corporation/Oracle WebLogic Server 14.1.2.0.0
Oracle Corporation/Oracle WebLogic Server 15.1.1.0.0
Published Jul 21, 2026
Tracked Since Jul 22, 2026