Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the Oracle WebLogic Server product allows an unauthenticated attacker having network access via the T3 or IIOP protocols to compromise the server. Successful exploitation can lead to full takeover of the WebLogic Server, resulting in a loss of confidentiality, integrity, and availability for applications and data controlled by that server. The vulnerability is severe enough to grant an attacker complete control, as reflected in the CVSS vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

Affected Systems

Affected Oracle WebLogic Server products include version 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. These are the specific releases listed as vulnerable and should be identified and patched accordingly.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity. The EPSS score of less than 1% indicates a very low but non‑zero probability of exploitation, but the high base score reflects the severe impact. This vulnerability remains exploitable from any networked location that can reach the T3 or IIOP endpoints, and attackers require no authentication and can execute actions without interacting with a user interface, making the attack path straightforward and high‑risk. The absence of a KEV listing does not reduce the urgency; the vulnerability remains a real threat.

Generated by OpenCVE AI on August 21, 2026 at 17:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle WebLogic Server patch or upgrade to a version not listed as affected
  • Restrict network access to WebLogic Server by configuring firewalls or ACLs to limit T3 and IIOP traffic to trusted hosts
  • Enable WebLogic security and enforce strong authentication, disabling unused services and ensuring that unauthenticated access is not possible

Generated by OpenCVE AI on August 21, 2026 at 17:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Server Takeover via T3/IIOP in Oracle WebLogic Server
Weaknesses CWE-200
CWE-284

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Server Takeover via T3/IIOP in Oracle WebLogic Server
Weaknesses CWE-200
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle weblogic Server
CPEs cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle weblogic Server
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Weblogic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T17:34:34.582Z

Reserved: 2026-07-08T15:51:55.577Z

Link: CVE-2026-60672

cve-icon Vulnrichment

Updated: 2026-08-20T17:34:30.526Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:38.723

Modified: 2026-08-21T13:57:10.483

Link: CVE-2026-60672

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T18:00:16Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function