Junglewise Threat Intelligence

CVE-2026-35311: Oracle WebLogic Server improper access control in Core component

CVE-2026-35311 · Severity: high · CVSS 8.8 · Published 2026-06-17

Technologies: Oracle WebLogic Server. Vendors: Oracle.

Executive brief

Oracle WebLogic Server, a widely used application server for hosting enterprise Java applications, contains a critical vulnerability in its Core component. An attacker with low-level user credentials can exploit this flaw over the network to gain full control of the server. This could lead to the theft of sensitive business data, disruption of critical services, and unauthorized access to the broader corporate network.

Technical details

A vulnerability in the Core component of Oracle WebLogic Server (versions 12.2.1.4.0 and 14.1.2.0.0) is classified as Improper Access Control (CWE-284). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to bypass security restrictions and achieve a complete takeover of the WebLogic Server instance, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation steps.

Affected products

  • Oracle WebLogic Server 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats