Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unauthenticated attackers can exploit Oracle WebLogic Server via the T3 or IIOP protocols to gain full control of the system. The flaw allows an attacker to take over the WebLogic instance, resulting in complete compromise of confidentiality, integrity, and availability. The CVSS 3.1 base score of 9.8 underscores the severity of the vulnerability, indicating that no privileges are required for exploitation.

Affected Systems

Oracle WebLogic Server is impacted. All supported releases listed as affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. These versions are widely deployed in enterprise environments and include the core components necessary for the exploitation described.

Risk and Exploitability

The vulnerability is network reachable via the T3 and IIOP interfaces and requires no authentication, making the attack surface very broad. With a CVSS score of 9.8 and an EPSS score of < 1%, the exploitation probability remains low, yet the severity of compromise is extremely high. The vulnerability is not yet listed in the CISA KEV catalog, but the severity and exposure suggest a high priority for remediation.

Generated by OpenCVE AI on August 21, 2026 at 15:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle WebLogic Server patches for the affected releases as described in the official Oracle security advisory
  • If the T3 or IIOP protocols are not required for your deployment, disable them or use network access controls to restrict inbound connections to trusted hosts
  • Place the WebLogic Server behind a firewall or reverse proxy and enforce strict role‑based access controls to limit exposure to the vulnerable interfaces

Generated by OpenCVE AI on August 21, 2026 at 15:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Takeover via T3/IIOP in Oracle WebLogic Server

Wed, 19 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle weblogic Server
CPEs cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle weblogic Server
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Weblogic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T18:07:21.843Z

Reserved: 2026-07-08T15:51:55.579Z

Link: CVE-2026-60696

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:39.317

Modified: 2026-08-21T13:55:59.723

Link: CVE-2026-60696

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T16:00:15Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function