Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in the WebLogic Server Console component that allows an attacker who can access the server over HTTPS to gain high privileged control. The flaw is sufficient to enable a full takeover of the Oracle WebLogic Server, resulting in loss of all confidentiality, integrity, and availability for the affected instance. The weakness is classified as CWE-306, indicating missing authentication for a sensitive function.

Affected Systems

Oracle Corporation’s WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0 are affected. These versions are delivered as part of Oracle Fusion Middleware and use the Console for administrative operations.

Risk and Exploitability

The CVSS 3.1 base score of 7.2 denotes high severity with full CIA impact. The EPSS score of less than 1% indicates that, while exploitation is feasible, it is rarely observed in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, requiring network access to the HTTPS console endpoint and a high privilege level on the target system.

Generated by OpenCVE AI on August 4, 2026 at 17:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Critical Patch Update released in July 2026 that addresses the WebLogic Console vulnerability.
  • Restrict external HTTPS access to the WebLogic Console by using firewall rules or a VPN that limits connectivity to trusted IP ranges.
  • If the Console component is not required for the deployment, consider disabling or removing it to reduce the attack surface.

Generated by OpenCVE AI on August 4, 2026 at 17:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Oracle WebLogic Console Remote Server Takeover Vulnerability

Tue, 28 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Oracle WebLogic Server Console Vulnerability Enables Remote Server Takeover
Weaknesses CWE-284
CWE-732

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269 CWE-306

Fri, 24 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Oracle WebLogic Server Console Vulnerability Enables Remote Server Takeover
Weaknesses CWE-284
CWE-732

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle weblogic Server
CPEs cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle weblogic Server
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Weblogic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:55:48.228Z

Reserved: 2026-07-08T15:51:40.514Z

Link: CVE-2026-60153

cve-icon Vulnrichment

Updated: 2026-07-23T15:21:54.441Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:15.873

Modified: 2026-07-28T05:17:07.413

Link: CVE-2026-60153

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:45:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function