Description
Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for Third-Party Web Servers). The supported version that is affected is 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle Weblogic Server Proxy Plug-in accessible data. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-07-21
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Oracle WebLogic Server Proxy Plug‑in component for third‑party web servers, enabling an unauthenticated attacker with network access via HTTP to compromise the plug‑in. Successful exploitation allows the attacker to create, delete, or modify critical data, or gain full unauthorized access to all proxied data, severely impacting confidentiality and integrity.

Affected Systems

This issue affects Oracle WebLogic Server Proxy Plug‑in version 15.1.1.0.0. Oracle HTTP Server release 12.2.1.4.0 and 14.1.2.0.0 are also listed as affected via the provided CPE entries, though the description specifically references the Proxy Plug‑in. Users should verify whether their installations match these vulnerable versions.

Risk and Exploitability

The CVSS score of 10.0 underscores critical severity, while an EPSS of <1% indicates a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires only network access to exposed HTTP interfaces, without authentication, meaning any host that can reach the plug‑in could attempt the exploit. The scope change noted in the description hints at potential privilege escalation, making this a highly risky flaw despite its low exploitation likelihood.

Generated by OpenCVE AI on August 4, 2026 at 04:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for the WebLogic Server Proxy Plug‑in (15.1.1.0.0).
  • Restrict network access to the plug‑in by limiting exposed HTTP endpoints to trusted internal hosts or subnets.
  • Enforce authentication or terminate SSL/TLS on the plug‑in to require credentials before service use.
  • Monitor logs for abnormal creation, deletion, or modification events in the plug‑in environment.

Generated by OpenCVE AI on August 4, 2026 at 04:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Proxy Plug‑in Exploit Enables Data Manipulation in Oracle Weblogic

Thu, 30 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Proxy Plug‑in Exploit Enables Data Manipulation in Oracle Weblogic

Mon, 27 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Control Vulnerability in Oracle WebLogic Server Proxy Plug‑in
Weaknesses CWE-285

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Control Vulnerability in Oracle WebLogic Server Proxy Plug‑in
Weaknesses CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for Third-Party Web Servers). The supported version that is affected is 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle Weblogic Server Proxy Plug-in accessible data. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle http Server
Oracle weblogic Server Proxy Plug-in
CPEs cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:http_server:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server_proxy_plug-in:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle http Server
Oracle weblogic Server Proxy Plug-in
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Http Server Weblogic Server Proxy Plug-in
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-01T03:55:48.639Z

Reserved: 2026-07-08T15:51:40.532Z

Link: CVE-2026-60365

cve-icon Vulnrichment

Updated: 2026-07-24T18:25:43.336Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:15:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function