Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in the Core component of Oracle WebLogic Server allows an unauthenticated attacker with network access via the T3 or IIOP protocols to compromise the server, potentially leading to full takeover. The flaw enables the attacker to achieve confidentiality, integrity, and availability impacts across the affected system, as indicated by CVSS 3.1 Base Score 8.1.

Affected Systems

It affects Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. The product is part of Oracle Fusion Middleware and is typically deployed in enterprise application environments.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity, while the EPSS < 1% suggests a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is over the network via the T3 or IIOP ports, and the weakness typifies improper use of a buggy or vulnerable component (CWE-306). Successful exploitation could result in an attacker gaining full control over the WebLogic Server.

Generated by OpenCVE AI on August 4, 2026 at 04:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle WebLogic Server patch released in the July 2026 CPU; the patch eliminates the vulnerability documented as CVE‑2026‑60312.
  • If patching cannot be done immediately, restrict inbound traffic on the T3 and IIOP ports for the WebLogic servers, or place the servers behind a firewall that blocks untrusted sources.
  • Enable strict authentication and access control settings in WebLogic, ensuring that all communications require TLS and limit access to authorized users, which mitigates the vulnerability.

Generated by OpenCVE AI on August 4, 2026 at 04:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Remote Takeover Vulnerability in Oracle WebLogic Server

Sat, 01 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Takeover via T3/IIOP in Oracle WebLogic Server

Sun, 26 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Takeover via T3/IIOP in Oracle WebLogic Server

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle weblogic Server
CPEs cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle weblogic Server
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Weblogic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-25T03:56:05.295Z

Reserved: 2026-07-08T15:51:40.529Z

Link: CVE-2026-60312

cve-icon Vulnrichment

Updated: 2026-07-23T17:45:49.910Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:30:04Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function