Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a critical remote code execution flaw in Oracle WebLogic Server that permits an unauthenticated attacker with network access to compromise the entire server, resulting in full takeover. The flaw leads to complete loss of confidentiality, integrity, and availability due to its ability to run arbitrary code on the affected platform.

Affected Systems

Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are affected; this includes both standard and fusion middleware deployments of Oracle WebLogic.

Risk and Exploitability

The CVSS 3.1 base score of 9.8 indicates extremely high severity. The EPSS score of less than 1% suggests low overall exploitation probability in the wild, but the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw through unauthenticated network connections to the server via the T3 or IIOP protocols, enabling full remote takeover with no credential or user interaction required.

Generated by OpenCVE AI on August 4, 2026 at 04:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU July 2026 security patch for WebLogic Server; the patch addresses the remote code execution flaw.
  • If a patch cannot be applied immediately, block inbound T3 and IIOP traffic from untrusted networks or place the WebLogic Server behind a firewall that permits only trusted hosts.
  • If source code or application restrictions are unavailable, consider removing or disabling the affected components from the network entirely and rely on network segmentation as a containment measure.

Generated by OpenCVE AI on August 4, 2026 at 04:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution Vulnerability in Oracle WebLogic Server via T3 and IIOP

Tue, 28 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle WebLogic Server via T3 and IIOP
Weaknesses CWE-94

Fri, 24 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle WebLogic Server via T3 and IIOP
Weaknesses CWE-94

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle weblogic Server
CPEs cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle weblogic Server
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Weblogic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-25T03:56:12.486Z

Reserved: 2026-07-08T15:51:40.522Z

Link: CVE-2026-60204

cve-icon Vulnrichment

Updated: 2026-07-23T16:04:18.581Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:00:05Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function