Junglewise Threat Intelligence

CVE-2026-35301: Oracle WebLogic Server authentication bypass in Console

CVE-2026-35301 · Severity: critical · CVSS 10 · Published 2026-06-17

Technologies: Oracle WebLogic Server. Vendors: Oracle Corporation, Oracle.

Executive brief

A critical vulnerability has been identified in the Console component of Oracle WebLogic Server, a platform used for building and deploying enterprise applications. This flaw allows an unauthorized person to gain full control over the server remotely without needing a username or password. An exploit could lead to a total compromise of the server, potentially impacting other connected business systems and resulting in the theft or destruction of sensitive data.

Technical details

This vulnerability is classified as a missing authentication for a critical function (CWE-306) within the Console component of Oracle WebLogic Server. It is easily exploitable by an unauthenticated attacker with network access via HTTP. The flaw allows for a complete takeover of the WebLogic Server instance (Confidentiality, Integrity, and Availability impacts). Due to a scope change (S:C), a successful exploit may also facilitate attacks against other integrated products or the underlying infrastructure. Affected versions include 12.2.1.4.0 and 14.1.1.0.0.

Affected products

  • Oracle Corporation WebLogic Server 12.2.1.4.0, 14.1.1.0.0

Timeline

  • 2026-06-17: disclosed: Initial disclosure by Oracle
  • 2026-06-17: advisory: NVD publication date

References

Related threats