Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle WebLogic Server’s core component allows an unauthenticated attacker with network access via the T3 or IIOP protocols to compromise the server. Successful exploitation can result in full server takeover, leaking or modifying sensitive data and disrupting service availability. The weakness is classified as a high‑impact flaw with a CVSS v3.1 base score of 8.1, indicating that confidentiality, integrity, and availability are all severely affected.

Affected Systems

Oracle Corporation’s WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are affected by this issue. Any deployment of these releases is susceptible to the described remote takeover vulnerability.

Risk and Exploitability

The vulnerability is difficult to exploit, yet an attacker with network access to the affected services can leverage it without authentication. The EPSS score is reported as less than 1 %, suggesting currently low exploitation probability, and the flaw is not listed in CISA’s KEV catalog. Nonetheless, the high CVSS score and the potential for complete server compromise warrant immediate remedial action.

Generated by OpenCVE AI on August 2, 2026 at 23:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or upgrade to a WebLogic Server version where the flaw is resolved.
  • Restrict inbound connections to the T3 and IIOP ports to trusted hosts only or place the servers behind a strict firewall rule set.
  • Disable or block the T3/IIOP services on any non‑essential endpoints to reduce the attack surface.

Generated by OpenCVE AI on August 2, 2026 at 23:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Remote Takeover via T3 or IIOP in Oracle WebLogic Server
Weaknesses CWE-285
CWE-862

Fri, 24 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Remote Takeover via T3 or IIOP in Oracle WebLogic Server
Weaknesses CWE-285
CWE-862

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle weblogic Server
CPEs cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle weblogic Server
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Weblogic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-25T03:56:20.766Z

Reserved: 2026-07-08T15:51:40.522Z

Link: CVE-2026-60201

cve-icon Vulnrichment

Updated: 2026-07-23T16:06:33.435Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T23:30:07Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function