Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a remote control flaw within the core component of Oracle WebLogic Server. A low‑privileged attacker with network connectivity to the T3 or IIOP protocols can leverage the weakness to take over the server, thereby gaining full control of the application, its data, and the underlying operating system. The impact includes confidentiality, integrity and availability losses across the affected system.

Affected Systems

Oracle Corporation’s WebLogic Server is affected. All listed releases are impacted: 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. These versions have been identified by the CNA as susceptible to the flaw and are still in support, meaning they remain relevant targets for attackers.

Risk and Exploitability

The quantified severity is a CVSS 3.1 base score of 7.5, indicating a high‑risk condition. EPSS data is not available, but the flaw is not in the CISA KEV list, suggesting it is not currently exploited in the wild. The attack path requires a low‑privileged attacker to reach the vulnerable host over the network, which typically means they must be on the same internal network or have opened the T3/IIOP ports externally. Given the known vector and the potential for full server control, the risk to organizations remains high.

Generated by OpenCVE AI on August 18, 2026 at 23:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor‑issued patch or cumulative update for the affected WebLogic Server versions.
  • Restrict inbound access to the T3 (default port 7001) and IIOP (default port 7002) interfaces by firewall rules or network segmentation.
  • Disable or harden any exposed administrative services and enforce strong authentication policies.

Generated by OpenCVE AI on August 18, 2026 at 23:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege Remote Takeover via T3/IIOP in Oracle WebLogic Server
Weaknesses CWE-284
CWE-863

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle weblogic Server
CPEs cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle weblogic Server
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Weblogic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:58:57.227Z

Reserved: 2026-07-08T15:51:55.577Z

Link: CVE-2026-60679

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:38.850

Modified: 2026-08-18T21:16:38.850

Link: CVE-2026-60679

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T23:15:04Z

Weaknesses