Black & White Path
Aug 3, 2026 · Information Security
CVE‑2026‑60206: Oracle WebLogic Server SAML Authentication Bypass (CVSS 9.9) – Full POC
Oracle disclosed a critical CVE‑2026‑60206 SAML authentication bypass in WebLogic Server Core (CVSS 9.9) affecting versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0, with a publicly available Python‑based POC that supports multiple attack modes, detection scripts, and remediation guidance.
Authentication BypassCVE-2026-60206InfoSec
0 likes · 7 min read
