Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an unauthenticated flaw in the Remote Method Invocation (RMI) component of Oracle WebLogic Server. An attacker who can reach the server over the network may exploit insufficient access control (CWE-284) to invoke privileged APIs, allowing remote execution of arbitrary code and eventual complete takeover. The flaw directly impacts confidentiality, integrity, and availability, as the attacker can read, modify, or delete data and disrupt the server’s operation.

Affected Systems

Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0 are affected. The issue is present in the WebLogic Server core components and is applicable to deployments that expose the RMI port over the network.

Risk and Exploitability

The CVSS 3.1 base score of 9.8 indicates critical severity, and the attack vector is network-based, requiring only open RMI access and no authentication. The EPSS score is less than 1% (approximately 0.00549), indicating a very low exploit probability, but the lack of authentication and the ability to execute arbitrary code still make this a high‑risk vulnerability. The vulnerability is not listed in CISA’s KEV catalog, yet the high score and known exploitation potential warrant immediate attention.

Generated by OpenCVE AI on August 21, 2026 at 20:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the most recent Oracle WebLogic Server patch or upgrade to a version that includes the fix.
  • Block or restrict external access to the RMI port using firewalls or network segmentation, limiting exposure to internal trusted networks only.
  • Enforce authentication and proper access control on RMI endpoints, ensuring only authorized users or services can invoke privileged operations.
  • Monitor system logs for suspicious RMI activity and review audit trails regularly to detect potential exploitation attempts.

Generated by OpenCVE AI on August 21, 2026 at 20:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated RMI Flaw Allows Remote Code Execution in Oracle WebLogic Server

Fri, 21 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via RMI in Oracle WebLogic Server
Weaknesses CWE-285

Fri, 21 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 21 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via RMI in Oracle WebLogic Server
Weaknesses CWE-285

Thu, 20 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle weblogic Server
CPEs cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle weblogic Server
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Weblogic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-21T16:47:28.566Z

Reserved: 2026-07-08T15:51:55.605Z

Link: CVE-2026-60977

cve-icon Vulnrichment

Updated: 2026-08-21T14:03:37.238Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:16:50.097

Modified: 2026-08-21T17:16:33.317

Link: CVE-2026-60977

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:00:03Z

Weaknesses