Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the Oracle WebLogic Server product allows an unauthenticated attacker having network access via the T3 or IIOP protocols to compromise the server. Successful exploitation can lead to full takeover of the WebLogic Server, resulting in a loss of confidentiality, integrity, and availability for applications and data controlled by that server. The vulnerability is severe enough to grant an attacker complete control, as reflected in the CVSS vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

Affected Systems

Affected Oracle WebLogic Server products include version 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. These are the specific releases listed as vulnerable and should be identified and patched accordingly.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity. Although no EPSS score is available, the lack of a KEV listing does not reduce the urgency; the vulnerability remains exploitable from any networked location that can reach the T3 or IIOP endpoints. Attackers require no authentication and can execute actions without interacting with a user interface, making the attack path straightforward and high‑risk. The absence of an EPSS score means that typical low probability estimates are unavailable, but the high CVSS and explicit network exploitability underscore the real threat.

Generated by OpenCVE AI on August 18, 2026 at 23:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle WebLogic Server patch or upgrade to a version not listed as affected
  • Restrict network access to WebLogic Server by configuring firewalls or ACLs to limit T3 and IIOP traffic to trusted hosts
  • Enable WebLogic security and enforce strong authentication, disabling unused services and ensuring that unauthenticated access is not possible

Generated by OpenCVE AI on August 18, 2026 at 23:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Server Takeover via T3/IIOP in Oracle WebLogic Server
Weaknesses CWE-200
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle weblogic Server
CPEs cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle weblogic Server
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Weblogic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:58:56.901Z

Reserved: 2026-07-08T15:51:55.577Z

Link: CVE-2026-60672

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:38.723

Modified: 2026-08-18T21:16:38.723

Link: CVE-2026-60672

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T23:30:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control