Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-08-18
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle WebLogic Server permits an unauthenticated attacker that can reach the server through the T3 or IIOP protocols to compromise the system. The vulnerability enables full access to any data that the server can reach, resulting in a high confidentiality breach. The weakness is an improper authentication or access‑control defect, consistent with CWE‑287 and CWE‑284.

Affected Systems

Affected Oracle WebLogic Server products are version 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. The attack may also extend to other Oracle Fusion Middleware components due to scope changes, so any environment that leverages WebLogic Server should be examined.

Risk and Exploitability

The CVSS score of 8.6 classifies this as a high‑risk vulnerability, and the lack of UI or authentication steps means it can be exploited by remote attackers without user interaction. EPSS data is unavailable and the vulnerability is not listed in CISA’s KEV, but the attack vector via network protocols suggests that exposure to the Internet or untrusted networks significantly increases the exploitation likelihood.

Generated by OpenCVE AI on August 18, 2026 at 23:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the Oracle WebLogic Server patch that addresses CVE-2026-60699, as detailed in the Oracle security alert.
  • If an immediate patch is not possible, block external access to the T3 and IIOP ports (default 7001/7002) using firewalls or network ACLs, allowing only trusted internal hosts to reach the WebLogic Server.
  • Conduct a security audit of deployed applications for unauthorized data exposure and monitor event logs for signs of suspicious authentication attempts.

Generated by OpenCVE AI on August 18, 2026 at 23:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Vulnerability in Oracle WebLogic Server via T3/IIOP
Weaknesses CWE-284
CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle weblogic Server
CPEs cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle weblogic Server
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Weblogic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:58:59.177Z

Reserved: 2026-07-08T15:51:55.579Z

Link: CVE-2026-60699

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:39.543

Modified: 2026-08-18T21:16:39.543

Link: CVE-2026-60699

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T23:15:04Z

Weaknesses