Executive brief
Oracle WebLogic Server, a widely used application server for deploying enterprise Java applications, contains a critical security flaw in its management console. An unauthenticated attacker can remotely take complete control of the server over the network. This could lead to the theft of sensitive business data, total service disruption, and may allow the attacker to compromise other connected corporate systems.
Technical details
A critical vulnerability exists in the Console component of Oracle WebLogic Server (versions 14.1.2.0.0 and 15.1.1.0.0) due to missing authentication for a critical function (CWE-306). The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Because the vulnerability allows for a 'scope change' (S:C), an attacker who compromises the WebLogic Server may be able to impact additional products or the underlying host environment. This vulnerability has been assigned the maximum CVSS score of 10.0, indicating total impact on confidentiality, integrity, and availability. Users should refer to the Oracle June 2026 Critical Patch Update for remediation steps.
Affected products
- Oracle WebLogic Server 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle
- 2026-06-17: advisory: NVD publication date