Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: TopLink Integration). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware, specifically the TopLink Integration component, permits a low‑privileged attacker who can reach the server over HTTP to compromise the server. Successful exploitation can result in a full takeover, giving the attacker control over confidentiality, integrity, and availability. The flaw is classified under CWE‑284 and is reflected in a CVSS v3.1 base score of 9.9, indicating a critical impact.

Affected Systems

The affected product is Oracle WebLogic Server. Vulnerable releases include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. These versions are part of the Oracle Fusion Middleware stack and are still supported at the time of the advisory. The TopLink Integration component is the point of entry for the vulnerability.

Risk and Exploitability

The CVSS score of 9.9 underscores a critical severity, while an EPSS score of less than 1% suggests that exploitation is currently rare but not impossible. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network‑based request to the WebLogic Server over HTTP; authentication is not required, and the attacker needs only low privileges, as indicated by the vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H.

Generated by OpenCVE AI on September 17, 2026 at 04:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch provided for CVE-2026-83038 or upgrade to a fixed version of Oracle WebLogic Server.
  • Restrict inbound HTTP access to the WebLogic Server by configuring firewalls or ACLs to allow only trusted hosts or internal networks.
  • Disable the TopLink Integration component if it is not required, or run it with the least privilege necessary.

Generated by OpenCVE AI on September 17, 2026 at 04:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via HTTP in Oracle WebLogic Server TopLink Integration

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: TopLink Integration). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle weblogic Server
CPEs cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle weblogic Server
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Weblogic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:25:13.312Z

Reserved: 2026-08-31T15:40:57.333Z

Link: CVE-2026-83038

cve-icon Vulnrichment

Updated: 2026-09-16T15:43:34.729Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-15T20:18:12.187

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83038

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T05:00:14Z

Weaknesses