CVE-2026-60206 is an XML Signature Wrapping vulnerability in the Core component of Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The flaw affects SAML assertion consumer service processing: signature validation can be performed independently from the assertion used to obtain the authenticated identity. An attacker can construct a SAML response containing an unsigned, attacker-controlled assertion before a separate validly signed assertion. If WebLogic validates the latter signature but extracts the NameID from the former assertion, it establishes a session for the attacker-selected identity.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a standalone Python proof-of-concept exploit for CVE-2026-60206, described as an Oracle WebLogic Server SAML authentication bypass. The repository is small and focused: README.md documents the vulnerability, usage, attack modes, and sample output; exploit.py is the main implementation; requirements.txt lists core and optional Python dependencies; LICENSE and .gitignore are standard support files. The main exploit logic resides in exploit.py, a large Python CLI tool with a shebang entry point and a main() function. It is not part of a larger exploitation framework. The script supports both single-target and mass-scan workflows, uses requests by default with optional httpx for HTTP/2, and optionally leverages lxml, signxml, and cryptography for richer XML/SAML handling. It includes concurrency via ThreadPoolExecutor, reporting via JSON/CSV, raw request replay support, proxy/Tor support, user-agent rotation, and retry/timeout tuning. Its core capability is web-based remote exploitation against WebLogic SAML endpoints. Based on the README and visible code structure, it fingerprints WebLogic versions, probes SAML-related endpoints, inspects SAML configuration, and then generates manipulated SAML 2.0 responses/assertions to attempt authentication bypass. Supported attack modes include unsigned assertion injection, XML Signature Wrapping, NameID manipulation, audience restriction bypass, conditions/time bypass, combined attacks, and replay of captured SAML responses. Successful exploitation is intended to authenticate as an arbitrary user such as 'weblogic' or 'admin'. Fingerprintable targets and artifacts include example HTTPS WebLogic targets on port 7002, the SAML ACS path /saml2/sp/acs, local input/output files such as targets.txt, results.json, results.csv, captured.xml, and request.txt, and numerous SAML namespace URNs embedded in the code for payload construction. Overall, this is a real exploit-oriented PoC rather than a mere detector, with operational features but no evidence of a highly modular or framework-integrated weaponized payload system.
Repository contains a standalone exploit toolkit for the claimed Oracle WebLogic SAML authentication bypass CVE-2026-60206, implemented in both Python and Bash, plus a lighter Bash verifier PoC. Structure is simple: README documentation, dependency list, one full Python scanner/exploit (exploit.py), one full Bash scanner/exploit (exploit.sh), and one reduced verifier (verifier_poc.sh). The code is not part of a known exploitation framework like Metasploit or Nuclei. Main capability is web-based pre-auth exploitation against Oracle WebLogic SAML endpoints. The tooling is designed to discover targets, identify WebLogic instances, enumerate or assume SAML ACS endpoints, generate forged base64-encoded SAML Response payloads, and submit them to the target to bypass authentication. The verifier script clearly shows unsigned SAML assertion generation with attacker-controlled NameID, Issuer, Audience, Recipient, timestamps, and destination fields. README claims multiple vectors including unsigned assertions, XML Signature Wrapping variants, NameID manipulation, and combo modes. Operational features indicate a fairly mature offensive toolkit: concurrent mass scanning, target loading from URL/list/Shodan, proxy auto-discovery, explicit proxy support, Tor routing via socks5h://127.0.0.1:9050, optional TLS verification disablement, session cookie saving/loading, output to JSON/CSV/JSONL, and summary/report generation. The Bash tooling parses result fields such as reachable, is_weblogic, version, vulnerable, saml_endpoints, exploit_success, exploited_user, exploit_mode, cookie, verified, and verification_details, which suggests the exploit attempts both detection and authenticated-session validation. Fingerprintable targets/endpoints present in the repository include SAML ACS paths /saml2/sp/acs and /saml2/acs, the post-exploitation admin surface /console, the hardcoded forged issuer https://evil-idp.com, Tor proxy socks5h://127.0.0.1:9050, example proxy http://127.0.0.1:8080, and local artifacts such as session.txt. Overall purpose: a multi-platform exploit/scanner intended to automate discovery, verification, and exploitation of vulnerable WebLogic SAML authentication flows to obtain administrative access and session cookies.
This repository is a standalone Python exploit toolkit for CVE-2026-60206, a claimed Oracle WebLogic Server SAML authentication bypass. It is not tied to a common exploitation framework. The repository contains a main exploit driver (CVE-2026-60206-exploit.py), a concurrent mass scanner (mass_scan.py), and helper modules for logging, SAML assertion manipulation, and WebLogic HTTP interaction. Primary capability: the code detects WebLogic instances, fingerprints version and exposed SAML-related endpoints, then attempts authentication bypass by submitting crafted SAML 2.0 responses/assertions to WebLogic SAML endpoints. Implemented attack modes include unsigned assertion injection, XML Signature Wrapping (multiple variants), NameID manipulation/comment injection, audience restriction bypass, conditions/time restriction bypass, and replay/token substitution. The exploit reports success when it observes indicators consistent with authenticated access as an attacker-chosen user. Repository structure: CVE-2026-60206-exploit.py is the main entry point and orchestrates detection, attack execution, and report generation. modules/samlib.py provides the SAML-building and tampering logic, including XML namespaces, assertion/response generation, signing support via signxml/cryptography, and attack-vector metadata. modules/weblogic_client.py implements HTTP session handling, retries, SSL/proxy options, WebLogic version detection, endpoint probing, fingerprinting, and success heuristics. mass_scan.py scales detection/exploitation across multiple targets concurrently and exports results. modules/logger.py provides colored console logging. Notable endpoints are concentrated in modules/weblogic_client.py and include numerous candidate SAML ACS/SSO/metadata paths plus WebLogic console, WSDL, management, and internal paths used for fingerprinting and post-auth success checks. Overall, this is an operational exploit PoC with a real attack workflow and customizable target/user inputs, but it does not appear to deliver a post-exploitation shell or arbitrary command execution payload; its end goal is authentication bypass and impersonated access.
Repository contains two Python scripts and one README. The primary file, CVE-2026-60206.py, is an exploit PoC targeting Oracle WebLogic Server SAML handling for CVE-2026-60206. It generates a forged SAML 2.0 Response with attacker-controlled username and elevated attributes (Administrators / weblogicAdministrators), base64-encodes it, and POSTs it to a configurable ACS path, defaulting to /saml2/acs. The script reports HTTP status outcomes and writes the returned HTML to saml_response.html. This is a real exploit PoC rather than just documentation, despite the README disclaimer claiming no exploit code is included. The second script, CVE-2026-60206-check.py, is a reconnaissance/detection helper rather than the exploit itself. It probes common WebLogic and SAML-related paths (/saml2/acs, /saml2, /console, /webconsole, /), checks for WebLogic-identifying Server headers, and flags likely SAML exposure. It does not exploit the target, but it supports target validation. Overall purpose: provide both a safe checker and an operational proof-of-concept for a network-accessible WebLogic SAML authentication/privilege-escalation issue. No external C2 or callback infrastructure is present; the only hardcoded remote identifier is the fake issuer https://evil-idp.com embedded in the forged assertion. The exploit is operational but basic, with a hardcoded payload structure and limited success validation based mainly on HTTP response codes.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical Oracle WebLogic Server Core vulnerability with CVSS 9.9 that requires low privileges and has scope change, enabling compromise beyond the WebLogic server itself.
A critical vulnerability affecting the core component of Oracle WebLogic Server.
An XML Signature Wrapping flaw in WebLogic SAML assertion processing that could allow an attacker to submit a multi-assertion SAML response, have a valid signature verified on one assertion, and have the identity taken from an unsigned attacker-controlled assertion, resulting in administrative-session authentication bypass.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.