Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle WebLogic Server allows a low‑privileged attacker with network access to HTTP to execute arbitrary code, resulting in takeover of the entire server. The CVSS V3.1 score of 8.8 indicates high severity with confidentiality, integrity and availability impacts. The flaw is consistent with improper access control or authentication weaknesses, which enable an attacker to bypass normal security checks and gain unrestricted control.

Affected Systems

Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0, part of Oracle Fusion Middleware’s Core component, are affected. The vulnerability applies to the HTTP management interface exposed by these releases.

Risk and Exploitability

The EPSS score of less than 1% implies exploit potential is currently low, yet the high CVSS score and lack of CISA KEV listing mean the risk remains significant. The likely attack vector is over the network using HTTP requests; an attacker requires only network connectivity to the WebLogic port and can exploit the flaw without additional privileges. Successful exploitation could compromise all data and services hosted on the affected server.

Generated by OpenCVE AI on August 2, 2026 at 22:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle WebLogic Server CPU July 2026 patch for versions 12.2.1.4.0 and 14.1.1.0.0.
  • If the patch cannot be applied immediately, restrict access to the WebLogic HTTP management port to trusted networks or disable the port entirely.
  • Implement monitoring and logging of HTTP requests to detect anomalous activity, and enforce stricter authentication and network security controls for the WebLogic environment.

Generated by OpenCVE AI on August 2, 2026 at 22:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title WebLogic Server HTTP Access Control Bypass Allowing Full Server Compromise

Tue, 28 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title HTTP-Based Remote Code Execution Leading to Server Takeover in Oracle WebLogic Server
Weaknesses CWE-287

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title HTTP-Based Remote Code Execution Leading to Server Takeover in Oracle WebLogic Server
Weaknesses CWE-284
CWE-287

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle weblogic Server
CPEs cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle weblogic Server
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Weblogic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-25T03:56:03.557Z

Reserved: 2026-07-08T15:51:40.531Z

Link: CVE-2026-60343

cve-icon Vulnrichment

Updated: 2026-07-24T19:14:19.010Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:45:17Z

Weaknesses