Junglewise Threat Intelligence

CVE-2026-35259: Oracle WebLogic Server open redirect in Console

CVE-2026-35259 · Severity: high · CVSS 8.8 · Published 2026-06-17

Technologies: Oracle WebLogic Server. Vendors: Oracle, Oracle Corporation.

Executive brief

Oracle WebLogic Server, a platform for developing and deploying enterprise applications, contains a vulnerability in its management console. An unauthenticated attacker could trick a legitimate user into performing an action that allows the attacker to take full control of the server. This could lead to the theft of sensitive data, service outages, or unauthorized access to internal business systems.

Technical details

A vulnerability in the Console component of Oracle WebLogic Server (versions 14.1.2.0.0 and 15.1.1.0.0) is classified as an Open Redirect (CWE-601) that can lead to full server takeover. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTPS. While the attack vector is network-based, successful exploitation requires user interaction (UI:R), typically involving a legitimate administrator clicking a malicious link or being redirected. If successful, the attacker can achieve high impacts on confidentiality, integrity, and availability, effectively compromising the entire WebLogic Server instance. Oracle has addressed this in the June 2026 security update.

Affected products

  • Oracle Corporation WebLogic Server 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle Critical Patch Update published

References

Related threats