Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle WebLogic Server allows an unauthenticated attacker with network connectivity to the T3 or IIOP ports to gain full control of the server. The flaw can be exploited without any prior authentication, and successful exploitation leads to complete takeover of the WebLogic instance, compromising confidentiality, integrity and availability of all data and services running on the server. The issue is a classic remote code execution vulnerability with the potential for widespread system compromise. The underlying issue is a CWE‑306 missing authentication flaw.

Affected Systems

Oracle WebLogic Server from versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0 is affected. Any instance of these releases exposed to the public network on the standard T3 or IIOP ports is vulnerable.

Risk and Exploitability

The CVSS v3.1 Base Score of 9.8 indicates a critical impact with high confidence that an attacker can exploit the flaw. The EPSS score of less than 1% is low, indicating that the probability of exploitation is currently low, yet the stock exploitation potential remains high due to the lack of authentication requirement. This vulnerability is not yet listed in the CISA KEV catalog, but the high severity and unauthenticated nature make it a priority target for attackers. The attack vector is inferred to be a network-based remote exploit via T3 or IIOP protocols, requiring no user interaction or credentials.

Generated by OpenCVE AI on August 4, 2026 at 04:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle WebLogic Server update referenced in Oracle’s July 2026 CPU to all affected versions
  • Restrict inbound traffic to the T3 and IIOP ports to only trusted networks or use firewall segmentation
  • Reconfigure WebLogic Server to bind its connectors to internal IP addresses only, effectively preventing remote access unless required, and disable unused administration interfaces

Generated by OpenCVE AI on August 4, 2026 at 04:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via T3/IIOP in Oracle WebLogic Server

Thu, 30 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via T3/IIOP in Oracle WebLogic Server

Sun, 26 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via T3/IIOP in Oracle WebLogic Server

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle weblogic Server
CPEs cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle weblogic Server
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Weblogic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:55:46.579Z

Reserved: 2026-07-08T15:51:40.521Z

Link: CVE-2026-60198

cve-icon Vulnrichment

Updated: 2026-07-23T16:12:25.341Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:00:05Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function