Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability in Oracle WebLogic Server’s Core component can be triggered by unauthenticated adversaries who have network reach to the T3 or IIOP interfaces. Once exploited the attacker gains full control of the server, compromising confidentiality, integrity, and availability. The CVSS v3.1 base score of 8.1 indicates a high-impact attack that can lead to a total system takeover.

Affected Systems

Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are vulnerable. These versions include the Core component susceptible to this flaw.

Risk and Exploitability

The vulnerability is difficult to exploit but has a high CVSS score, meaning significant potential damage if successful. EPSS data is unavailable, so the likelihood of exploitation is not quantified, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need network connectivity to the vulnerable protocols, with no user interaction required; once the flaw is triggered, the server can be fully compromised.

Generated by OpenCVE AI on August 18, 2026 at 23:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch available for the affected WebLogic Server releases as announced in the security alert
  • If patching is delayed, restrict inbound traffic to the T3 and IIOP ports to only trusted hosts or internal networks
  • Consider disabling or limiting the use of T3 and IIOP protocols on public-facing interfaces to reduce the attack surface

Generated by OpenCVE AI on August 18, 2026 at 23:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via T3/IIOP in Oracle WebLogic Server
Weaknesses CWE-20

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle weblogic Server
CPEs cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle weblogic Server
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Weblogic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:58:55.285Z

Reserved: 2026-07-08T15:51:40.535Z

Link: CVE-2026-60415

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:38.130

Modified: 2026-08-18T21:16:38.130

Link: CVE-2026-60415

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T23:30:04Z

Weaknesses
  • CWE-20

    Improper Input Validation