Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:N).
Published: 2026-07-21
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle WebLogic Server’s Console component has an authorization flaw that lets a high‑privileged attacker with network access over HTTP create, delete, or modify data in the server and, in some cases, read other data. The vulnerability permits unauthorized administrative changes that can compromise confidentiality and integrity of critical information.

Affected Systems

Oracle WebLogic Server versions 14.1.2.0.0 and 15.1.1.0.0 are vulnerable when the administrative console is exposed over HTTP.

Risk and Exploitability

The CVSS base score of 7.6 indicates high severity, yet the EPSS score of less than 1% shows a low probability of exploitation currently. Attackers would use the console over HTTP to gain elevated privileges, potentially affecting other applications that rely on the same WebLogic instance. Although the flaw is not listed in CISA’s KEV catalog, its severity warrants the same level of attention as any CVSS 7.6 vulnerability.

Generated by OpenCVE AI on August 2, 2026 at 22:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the July 2026 Oracle Critical Patch Update that addresses the WebLogic Console flaw.
  • Restrict HTTP access to the WebLogic console to trusted internal networks or VPNs so only authorized hosts can reach it.
  • Configure logging and monitoring to alert on unexpected console administration activity, and consider disabling unused console features if possible.

Generated by OpenCVE AI on August 2, 2026 at 22:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Title Oracle WebLogic Server Console Authorization Flaw Allows High-Privilege Data Manipulation

Sat, 01 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Unauthorized data modification via Oracle WebLogic Server Console

Sun, 26 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Unauthorized data modification via Oracle WebLogic Server Console

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:N).
First Time appeared Oracle
Oracle weblogic Server
CPEs cpe:2.3:a:oracle:weblogic_server:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle weblogic Server
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:N'}


Subscriptions

Oracle Weblogic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-25T03:55:56.546Z

Reserved: 2026-07-08T15:51:40.543Z

Link: CVE-2026-60528

cve-icon Vulnrichment

Updated: 2026-07-24T19:01:31.994Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:15:03Z

Weaknesses