Junglewise Threat Intelligence

CVE-2026-35291: Oracle WebLogic Server privilege management vulnerability in Console

CVE-2026-35291 · Severity: medium · CVSS 6.6 · Published 2026-06-17

Technologies: Oracle WebLogic Server. Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability exists in the Console component of Oracle WebLogic Server, a platform used for building and deploying enterprise applications. A highly privileged attacker could exploit this flaw to gain full control over the server. While the attack is difficult to execute, a successful compromise could lead to a total loss of data confidentiality and service availability.

Technical details

This vulnerability is classified as improper privilege management (CWE-269) within the Console component of Oracle WebLogic Server. It is accessible via the HTTP protocol over a network. Exploitation requires high privileges and is characterized by high complexity, suggesting specific environmental conditions or timing are necessary for success. If successfully exploited, an attacker can achieve a complete takeover of the WebLogic Server instance, impacting confidentiality, integrity, and availability. The vulnerability affects versions 14.1.2.0.0 and 15.1.1.0.0.

Affected products

  • Oracle Corporation WebLogic Server 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-06-17: disclosed: Initial disclosure by Oracle
  • 2026-06-17: advisory: NVD publication date

References

Related threats