Executive brief
Oracle WebLogic Server is a platform used to build and deploy enterprise Java applications. A critical vulnerability in its core component allows a high-privileged user to take full control of the server over the network. This could lead to a complete service outage, theft of sensitive business data, and potential unauthorized access to other connected systems within the corporate environment.
Technical details
An improper access control vulnerability (CWE-284) exists in the Core component of Oracle WebLogic Server. The flaw is easily exploitable by a high-privileged attacker with network access via HTTP. While the vulnerability resides within WebLogic, it features a 'scope change' (S:C), meaning a successful exploit can impact resources beyond the security scope of the WebLogic Server itself, potentially leading to a total takeover of the host or integrated systems. Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Users should refer to the Oracle Critical Patch Update for June 2026 for remediation.
Affected products
- Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle published security alert CSPUJUN2026