Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SAML to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a missing authentication or authorization check in the core component of Oracle WebLogic Server, identified as CWE‑306. It allows a low‑privileged attacker with network reach to exploit the server through SAML authentication. Successful exploitation results in complete takeover of the server, compromising confidentiality, integrity and availability, and potentially affecting other products that depend on WebLogic.

Affected Systems

Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are impacted. These versions are part of Oracle Fusion Middleware and are frequently deployed in enterprise environments.

Risk and Exploitability

The CVSS 3.1 base score of 9.9 indicates critical severity. The EPSS score of <1% suggests a very low current probability of exploitation, and the issue is not listed in the CISA KEV catalog. Nevertheless, the vulnerability can be triggered remotely over the network, requires only low privileges, and grants full control of the server, enabling data exfiltration, service disruption, or lateral movement.

Generated by OpenCVE AI on August 4, 2026 at 04:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the July 2026 CPU patch for Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 from Oracle’s security website.
  • If the patch cannot be applied immediately, block or disable the SAML authentication endpoints to prevent exploitation.
  • After remediation, implement strict network segmentation around the WebLogic servers and monitor authentication logs for suspicious activities.

Generated by OpenCVE AI on August 4, 2026 at 04:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Oracle WebLogic Server Core Vulnerability Allowing Remote Takeover via SAML
Weaknesses CWE-284

Fri, 24 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287 CWE-306

Fri, 24 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Oracle WebLogic Server Core Vulnerability Allowing Remote Takeover via SAML
Weaknesses CWE-284

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SAML to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle weblogic Server
CPEs cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle weblogic Server
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Weblogic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-25T03:56:10.887Z

Reserved: 2026-07-08T15:51:40.523Z

Link: CVE-2026-60206

cve-icon Vulnrichment

Updated: 2026-07-23T16:02:42.832Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:45:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function