Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle WebLogic Server is vulnerable to a flaw that allows an unauthenticated attacker who can reach the server over HTTP to execute code on the host. The weakness stems from missing authentication for a critical function (CWE‑306) and can result in a complete takeover of the WebLogic Server, compromising confidentiality, integrity, and availability of any applications or data it hosts.

Affected Systems

The affected product is Oracle WebLogic Server, part of Oracle Fusion Middleware. The vulnerable Core component is present in versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.

Risk and Exploitability

The CVSS v3.1 base score of 9.8 indicates a critical severity, while the EPSS score of < 1 % shows that the likelihood of exploitation at this time is low. The vulnerability is not yet listed in CISA’s KEV catalog. Attackers can exploit the flaw by sending crafted HTTP requests to a vulnerable WebLogic Server instance over the network, without needing authentication, potentially leading to full system compromise.

Generated by OpenCVE AI on August 4, 2026 at 04:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle WebLogic Server patch released in the July 2026 Critical Patch Update for all affected versions.
  • Restart the WebLogic Server after patching to activate the fix.
  • Disable or restrict the core administrative interfaces and enforce HTTPS for all management traffic, ensuring that only authenticated users can access these functions.
  • Configure network firewalls or access controls to limit inbound HTTP/HTTPS connections to trusted IP ranges only.

Generated by OpenCVE AI on August 4, 2026 at 04:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Unauthorized HTTP Access Enables Complete Compromise of Oracle WebLogic Server

Tue, 28 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Code Execution in Oracle WebLogic Server

Fri, 24 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Code Execution in Oracle WebLogic Server

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle weblogic Server
CPEs cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle weblogic Server
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Weblogic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:55:43.788Z

Reserved: 2026-07-08T15:51:40.521Z

Link: CVE-2026-60199

cve-icon Vulnrichment

Updated: 2026-07-23T16:11:02.983Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:00:05Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function