Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability in Oracle WebLogic Server’s Core component allows an unauthenticated attacker with network access through the T3 or IIOP protocols to compromise the server. A successful exploit results in full server takeover, exposing confidential data, altering or deleting system files, and disrupting service availability. The weakness, classified as CWE-200, is rated with a CVSS v3.1 base score of 8.1, reflecting significant impacts to confidentiality, integrity and availability.

Affected Systems

Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0 are affected. These releases include the Core component that is vulnerable to this flaw.

Risk and Exploitability

The exploit is difficult, but the issue carries a high CVSS score, signaling severe potential damage if successful. The EPSS score of less than 1 % indicates a low probability of exploitation in the current threat landscape. Attackers require network connectivity to the vulnerable T3 or IIOP ports and do not need user interaction; once the flaw is triggered, the server can be fully compromised. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 21, 2026 at 17:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch for the affected WebLogic Server releases as announced in the security alert
  • If patching is delayed, restrict inbound traffic to the T3 and IIOP ports to only trusted hosts or internal networks
  • Consider disabling or limiting the use of T3 and IIOP protocols on public‑facing interfaces to reduce the attack surface

Generated by OpenCVE AI on August 21, 2026 at 17:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated remote code execution via T3/IIOP in Oracle WebLogic Server

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via T3/IIOP in Oracle WebLogic Server
Weaknesses CWE-20

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Tue, 18 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via T3/IIOP in Oracle WebLogic Server
Weaknesses CWE-20

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle weblogic Server
CPEs cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle weblogic Server
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Weblogic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T17:17:37.992Z

Reserved: 2026-07-08T15:51:40.535Z

Link: CVE-2026-60415

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:38.130

Modified: 2026-08-21T13:57:36.510

Link: CVE-2026-60415

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T18:00:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor