Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the core component of Oracle WebLogic Server arises from an absence of proper authentication controls for certain privileged operations. The vulnerability enables a low‑privileged attacker with network access over HTTP to trigger code execution paths that bypass expected authorization checks, leading to full compromise of the server. The described impact touches all confidentiality, integrity, and availability aspects, allowing the attacker to execute arbitrary code and seize control of the WebLogic installation.

Affected Systems

Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.2.0.0, used as part of Oracle Fusion Middleware, are affected by this issue.

Risk and Exploitability

The CVSS v3.1 base score of 8.8 indicates a high severity risk, while the EPSS score of less than 1 % suggests the current exploitation probability is low. The vulnerability is not listed in the CISA KEV catalog. The attack vector is network‑based over HTTP, requiring only low privileges to trigger the exploit and attain full server takeover. The missing authentication requirement is inferred from the CVSS vector and the description of the attacker’s low privilege level.

Generated by OpenCVE AI on August 4, 2026 at 04:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle WebLogic Server security patch released in the July 2026 critical patch update.
  • Enforce authentication for all core component requests; if the patch cannot be applied immediately, restrict the WebLogic Server’s HTTP endpoints to trusted IP addresses and require authentication to access them.
  • Disable or limit any unused HTTP or REST interfaces on the server to reduce the attack surface.
  • Plan an upgrade to a newer WebLogic Server release that incorporates the fix if immediate patching is not feasible.

Generated by OpenCVE AI on August 4, 2026 at 04:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in Oracle WebLogic Server Core Allows Server Takeover

Thu, 30 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Vulnerability Enables Server Takeover in Oracle WebLogic Server

Fri, 24 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Vulnerability Enables Server Takeover in Oracle WebLogic Server

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle weblogic Server
CPEs cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle weblogic Server
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Weblogic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-25T03:56:10.057Z

Reserved: 2026-07-08T15:51:40.523Z

Link: CVE-2026-60207

cve-icon Vulnrichment

Updated: 2026-07-23T16:01:47.343Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:45:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function