Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).
Published: 2026-08-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker with low privileges to exploit the WebLogic Server via an HTTP request. Successful exploitation results in unauthorized creation, deletion or modification of critical data, and the ability to cause the server to hang or crash repeatedly. The CVSS v3.1 score of 8.1 reflects high impact on integrity and availability, with no impact on confidentiality.

Affected Systems

Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0 are affected. The flaw resides in the Core component of Oracle Fusion Middleware.

Risk and Exploitability

The vulnerability is network‑based and exploitable over HTTP with minimal attacker privileges. The EPSS score is < 1%, indicating a low exploitation probability, and the issue is not listed in the CISA KEV catalog, but the high CVSS base score indicates a severe risk. Attackers can target any exposed WebLogic Server instance, potentially compromising data integrity and causing service outages. The exploit does not require authentication, making it accessible to low‑privileged or unauthenticated users with network reach.

Generated by OpenCVE AI on August 21, 2026 at 15:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch for WebLogic Server to the affected versions as released by Oracle.
  • Restrict HTTP access to the WebLogic Server by using firewall rules or VPN to limit traffic to trusted internal networks.
  • Disable or tightly secure the WebLogic Administration Console and enforce role‑based access controls on the server.

Generated by OpenCVE AI on August 21, 2026 at 15:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title HTTP Attack Allows Low‑Privilege Data Modification and DoS in Oracle WebLogic Server

Wed, 19 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).
First Time appeared Oracle
Oracle weblogic Server
CPEs cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle weblogic Server
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Oracle Weblogic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T14:04:31.125Z

Reserved: 2026-07-08T15:51:55.577Z

Link: CVE-2026-60680

cve-icon Vulnrichment

Updated: 2026-08-19T14:04:25.608Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:38.967

Modified: 2026-08-21T13:56:21.113

Link: CVE-2026-60680

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T16:00:15Z

Weaknesses