Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability in Oracle WebLogic Server permits an attacker with low privileges to gain full control of the server when the attacker can reach the T3 or IIOP interfaces over the network. Because the exploit requires only basic network connectivity and does not need user interaction, it is considered easily exploitable. The CVSS 3.1 base score of 9.9 reflects complete confidentiality, integrity, and availability impacts.

Affected Systems

Affected versions are Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The flaw’s impact spans a scope change, meaning that compromise of the WebLogic instance could propagate to other applications or services running on the same host or virtual environment, extending the damage beyond the initial target. Network protocols required for exploitation are T3 and IIOP, providing a fixed entry point for attackers who can reach the server.

Risk and Exploitability

The risk is high because the CVSS score of 9.9 signals critical severity, and the EPSS score is reported as less than 1%, indicating a very low but non‑zero probability of exploitation. The vulnerability is not yet listed in CISA’s KEV catalog, but the remote nature of the attack and the potential to affect additional products suggests that it should be treated with urgency. Successful exploitation results in an attacker assuming the same privileges as the WebLogic process, giving full control over the server and any deployed applications.

Generated by OpenCVE AI on August 21, 2026 at 16:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle WebLogic Server security patch or upgrade to a version that includes the fix as identified in the official Oracle advisory.
  • Enforce proper access control according to CWE‑284 by ensuring only authorized roles can access management interfaces and reject any traffic from unauthorized users.
  • Restrict inbound access to T3 and IIOP ports by allowing traffic only from trusted internal hosts or subnets, and disable the protocols if they are not required.
  • Apply network segmentation and firewall rules to block external access to WebLogic management interfaces, and enable auditing of authentication attempts to detect potential exploitation.

Generated by OpenCVE AI on August 21, 2026 at 16:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution in Oracle WebLogic Server via T3/IIOP

Wed, 19 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle weblogic Server
CPEs cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle weblogic Server
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Weblogic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T18:01:07.583Z

Reserved: 2026-07-08T15:51:55.579Z

Link: CVE-2026-60702

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:39.660

Modified: 2026-08-21T13:54:55.407

Link: CVE-2026-60702

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T16:45:03Z

Weaknesses