Junglewise Threat Intelligence

CVE-2026-35299: Oracle WebLogic Server authentication bypass in Console

CVE-2026-35299 · Severity: high · CVSS 8.8 · Published 2026-06-17

Technologies: Oracle WebLogic Server. Vendors: Oracle.

Executive brief

A vulnerability exists in the Console component of Oracle WebLogic Server, a platform used for building and deploying enterprise applications. An attacker with low-level access to the network can exploit this flaw to take full control of the server. This could lead to the theft of sensitive data, disruption of business operations, and unauthorized changes to the application environment.

Technical details

A vulnerability in the Console component of Oracle WebLogic Server (versions 12.2.1.4.0 and 14.1.1.0.0) is classified as a missing authentication for a critical function (CWE-306). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to achieve a complete takeover of the WebLogic Server, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation steps.

Affected products

  • Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats