Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is caused by missing authentication controls (CWE‑306). A low‑privileged attacker with network access through HTTP can exploit the flaw in the Core component of Oracle WebLogic Server, enabling the attacker to compromise the server and gain full control. The lack of proper authentication leads to confidentiality, integrity, and availability impacts, effectively allowing remote code execution and server takeover.

Affected Systems

Affected by Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. These versions are part of the Fusion Middleware stack and may be deployed in enterprise data centers or cloud environments.

Risk and Exploitability

The CVSS 3.1 base score of 8.8 reflects a high severity. The EPSS score is under 1%, indicating a relatively low probability of current exploitation, and the vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector is unsecured HTTP traffic accessible over the network; exploitation requires only low‑privilege credentials and can lead to full server compromise.

Generated by OpenCVE AI on August 2, 2026 at 23:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the public patch for affected WebLogic Server versions from the Oracle security advisory.
  • Restrict HTTP access to the WebLogic Server management console and REST endpoints, allowing only trusted hosts or VPNs.
  • Monitor incoming HTTP traffic for anomalous requests and review WebLogic logs for unauthorized sign‑in attempts.

Generated by OpenCVE AI on August 2, 2026 at 23:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via HTTP in Oracle WebLogic Server 12.2.1.4.0–15.1.1.0.0
Weaknesses CWE-284
CWE-79

Fri, 24 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via HTTP in Oracle WebLogic Server 12.2.1.4.0–15.1.1.0.0
Weaknesses CWE-284
CWE-79

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle weblogic Server
CPEs cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle weblogic Server
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Weblogic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-25T03:56:18.893Z

Reserved: 2026-07-08T15:51:40.522Z

Link: CVE-2026-60203

cve-icon Vulnrichment

Updated: 2026-07-23T16:05:00.781Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T23:30:07Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function