Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle WebLogic Server executes to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-07-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability, a CWE-284 Weakness in the Oracle WebLogic Server console component, allows an unauthenticated attacker with local system access to read protected configuration data. It does not provide arbitrary code execution, but the compromised data can include credentials, debugging information, and other highly confidential information. Because the flaw changes the scope, a successful exploitation may also enable the attacker to access other applications that run on the same WebLogic instance, extending the confidentiality impact beyond the original console service.

Affected Systems

Oracle WebLogic Server versions 14.1.2.0.0 and 15.1.1.0.0 are affected, specifically the console module of these releases.

Risk and Exploitability

The CVSS Base score of 7.1 indicates high severity, with low attack complexity, no privileges required, and no user interaction. The EPSS score of less than 1% suggests that exploitation is currently rare, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is local: the attacker must already have access to the infrastructure where WebLogic is running. From that position, the console flaw can be used to read protected data, and the scope change can extend access to other components that share the same WebLogic instance.

Generated by OpenCVE AI on August 4, 2026 at 03:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest Oracle WebLogic Server release that addresses the console bug, as detailed in Oracle’s latest security advisory.
  • Restrict access to the WebLogic Administration Console to known management hosts or internal networks, using firewall rules or IP allowlists.
  • Enable and review audit logging for console access attempts, and investigate any suspicious activity promptly.

Generated by OpenCVE AI on August 4, 2026 at 03:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Title Local Unauthenticated Access to Oracle WebLogic Server Console Enables Data Exfiltration

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Oracle WebLogic Server Console Privilege Escalation Vulnerability
Weaknesses CWE-200

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Oracle WebLogic Server Console Privilege Escalation Vulnerability
Weaknesses CWE-200
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle WebLogic Server executes to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle weblogic Server
CPEs cpe:2.3:a:oracle:weblogic_server:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle weblogic Server
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Weblogic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-25T03:55:59.747Z

Reserved: 2026-07-08T15:51:40.542Z

Link: CVE-2026-60527

cve-icon Vulnrichment

Updated: 2026-07-24T19:09:36.555Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:45:03Z

Weaknesses