Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle WebLogic Server enables an attacker to control the server without authenticating, using standard HTTP traffic. Once exploited, the attacker can read, modify, or delete data, and even run arbitrary code, effectively taking over the application environment. The vulnerability is identified as a high‑severity flaw with a CVSS 3.1 score of 9.8, indicating full confidentiality, integrity, and availability compromise for any vulnerable instance.

Affected Systems

Oracle Corporation’s WebLogic Server, specifically versions 12.2.1.4.0 and 14.1.1.0.0, are affected. These versions are part of Oracle Fusion Middleware’s Core component. No additional vendor or product variants are listed as impacted.

Risk and Exploitability

The attack vector is likely through normal network exposure: an unauthenticated user can send request via HTTP to the server and trigger the flaw. The CVSS score reflects that the exploit is easy and can be performed remotely without prior access or special credentials. The EPSS score is reported as <1%, implying that the probability of exploitation at any given moment is low, but the high severity and lack of proof of concepts in public advisories mean that a discovered vulnerability could be leveraged by a determined adversary. The vulnerability is not currently listed in the CISA KEV catalog, indicating no publicly known active attacks yet, but its potential consequences warrant immediate attention.

Generated by OpenCVE AI on August 4, 2026 at 04:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the Oracle WebLogic Server patch released in July 2026 per the vendor advisory
  • Restrict HTTP access to the WebLogic administrative console to trusted internal networks or VPNs
  • Monitor access logs for abnormal behavior or repeated exploitation attempts

Generated by OpenCVE AI on August 4, 2026 at 04:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Unauthenticated HTTP Access in Oracle WebLogic Server

Thu, 30 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Unauthenticated HTTP Access in Oracle WebLogic Server

Mon, 27 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Oracle WebLogic Server Remote Code Execution via Unauthenticated HTTP Access
Weaknesses CWE-284
CWE-307

Fri, 24 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Oracle WebLogic Server Remote Code Execution via Unauthenticated HTTP Access
Weaknesses CWE-284
CWE-307

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle weblogic Server
CPEs cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle weblogic Server
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Weblogic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-25T03:56:07.666Z

Reserved: 2026-07-08T15:51:40.528Z

Link: CVE-2026-60292

cve-icon Vulnrichment

Updated: 2026-07-23T18:32:10.952Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:30:04Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function