Junglewise Threat Intelligence

CVE-2026-35303: Oracle WebLogic Server auth bypass in Console

CVE-2026-35303 · Severity: high · CVSS 8.8 · Published 2026-06-17

Technologies: Oracle WebLogic Server. Vendors: Oracle.

Executive brief

Oracle WebLogic Server, a widely used application server for hosting enterprise Java applications, contains a vulnerability in its management console. An attacker with low-level user credentials can exploit this flaw over the network to gain full control of the server. This could lead to the theft of sensitive business data, unauthorized modification of applications, or a complete shutdown of the service.

Technical details

A vulnerability in the Console component of Oracle WebLogic Server (versions 12.2.1.4.0 and 14.1.1.0.0) is classified as a missing authentication for a critical function (CWE-306). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to bypass security controls and achieve a complete takeover of the WebLogic Server instance, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation steps.

Affected products

  • Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle released the security alert.

References

Related threats