Executive brief
Oracle WebLogic Server, a widely used application server for hosting enterprise Java applications, contains a critical security vulnerability in its core component. An attacker with basic user credentials can exploit this over the network to gain full control of the server. This could lead to the theft of sensitive data, disruption of business operations, and potential unauthorized access to other connected systems within the corporate network.
Technical details
A critical vulnerability exists in the Core component of Oracle WebLogic Server versions 14.1.2.0.0 and 15.1.1.0.0. Classified as an improper access control issue (CWE-284), it allows a low-privileged attacker with network access via HTTP to fully compromise the server. The vulnerability is characterized by a 'scope change' (S:C), meaning an exploit can impact resources beyond the WebLogic Server itself. No user interaction is required for exploitation. Oracle has addressed this in the June 2026 Critical Patch Update, and users are advised to apply the latest security patches immediately.
Affected products
- Oracle WebLogic Server 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle June 2026 Critical Patch Update published