Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS - Web Services). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-07-21
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated attacker who can reach Oracle WebLogic Server over standard HTTP can bypass authentication and gain unrestricted access to data exposed by the Web Services component. The vulnerability, classified under CVSS 3.1 with a base score of 8.6, reflects a high confidentiality impact while integrity and availability are not affected. The scope change indicates that the compromise could potentially extend beyond the initial service to other integrated components.

Affected Systems

Oracle WebLogic Server – versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0 are affected. These versions are part of Oracle Fusion Middleware and may be deployed on multiple application platforms.

Risk and Exploitability

The CVSS score of 8.6 places the vulnerability in the High range, and the EPSS score of less than 1% suggests that exploitation instances are currently rare but not impossible. Because the vulnerability is reachable over normal HTTP traffic and requires no authentication, an attacker could mount the exploit from any network that can reach the server without additional credentials. The lack of a KEV listing does not reduce the urgency; the attack surface and the potential impact on confidential data remain significant.

Generated by OpenCVE AI on August 5, 2026 at 02:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle WebLogic security patch released in the CPU Jul 2026 advisory to all impacted versions, which addresses the CWE‑200 Information Exposure flaw.
  • Configure the Web Services component to restrict data exposure, following CWE‑200 guidance: limit public endpoints, enforce role‑based access, and remove unused REST services.
  • Restrict inbound HTTP traffic to the WebLogic Server to authorized IP ranges or VPNs, using firewall rules or network segmentation.
  • Disable unused services and enforce strict access controls in the Web Services configuration, following Oracle's best‑practice guidelines.
  • Continuously monitor audit logs for anomalous authentication attempts.

Generated by OpenCVE AI on August 5, 2026 at 02:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Exposes Sensitive Data in Oracle WebLogic Server

Sat, 01 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Exploit in Oracle WebLogic Server

Sun, 26 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Exploit in Oracle WebLogic Server

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS - Web Services). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle weblogic Server
CPEs cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle weblogic Server
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Weblogic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T18:33:51.610Z

Reserved: 2026-07-08T15:51:40.528Z

Link: CVE-2026-60293

cve-icon Vulnrichment

Updated: 2026-07-23T18:33:30.956Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:15:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor