Executive brief
Oracle WebLogic Server, a widely used platform for developing and deploying enterprise Java applications, contains a critical security vulnerability in its core component. An unauthenticated attacker can exploit this flaw over a network to gain complete control of the server. This could lead to the theft of sensitive business data, disruption of critical operations, or the use of the server as a foothold for further attacks within the corporate network.
Technical details
A critical vulnerability exists in the Core component of Oracle WebLogic Server, classified as CWE-502 (Deserialization of Untrusted Data). The flaw allows an unauthenticated attacker with network access via TCP to send a specially crafted request that triggers insecure deserialization. Successful exploitation grants the attacker full control over the WebLogic Server instance, impacting confidentiality, integrity, and availability. The vulnerability affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Users are advised to refer to the Oracle Critical Patch Update (CPU) for June 2026 for remediation steps.
Affected products
- Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory