Junglewise Threat Intelligence

CVE-2026-35258: Oracle WebLogic Server open redirect in Console

CVE-2026-35258 · Severity: high · CVSS 8.7 · Published 2026-06-17

Technologies: Oracle WebLogic Server. Vendors: Oracle.

Executive brief

A vulnerability exists in the Console component of Oracle WebLogic Server, a platform used for building and deploying enterprise applications. An attacker with low-level access can trick a legitimate user into performing an action that allows the attacker to view, modify, or delete sensitive business data. This could lead to a significant breach of confidentiality and data integrity across the server and connected systems.

Technical details

This vulnerability is classified as an Open Redirect (CWE-601) within the Console component of Oracle WebLogic Server. It is easily exploitable by a low-privileged attacker with network access via HTTPS. The attack requires user interaction (UI:R) from a victim, such as clicking a malicious link, which then allows the attacker to achieve a scope change (S:C). Successful exploitation grants the attacker unauthorized high-impact access to read, create, delete, or modify critical data within WebLogic Server and potentially integrated downstream systems. Affected versions include 14.1.2.0.0 and 15.1.1.0.0.

Affected products

  • Oracle WebLogic Server 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats