Junglewise Threat Intelligence

CVE-2026-46848: Oracle WebLogic Server data compromise in Console

CVE-2026-46848 · Severity: high · CVSS 7.9 · Published 2026-06-17

Technologies: Oracle WebLogic Server. Vendors: Oracle, Oracle Corporation.

Executive brief

Oracle WebLogic Server, a platform for developing and deploying enterprise applications, contains a vulnerability in its management console. A low-privileged attacker with local access to the server could trick another user into performing an action that grants the attacker full control over WebLogic data. This could lead to the unauthorized theft, modification, or deletion of sensitive business information and potentially impact other connected systems.

Technical details

A vulnerability in the Console component of Oracle WebLogic Server (versions 14.1.2.0.0 and 15.1.1.0.0) allows a low-privileged attacker with local infrastructure access to compromise the system. The exploit requires human interaction from a user other than the attacker (UI:R) and results in a scope change (S:C), meaning the impact can extend beyond the WebLogic Server itself. Successful exploitation can lead to unauthorized access, modification, or deletion of all data accessible by the WebLogic Server. The attack vector is local (AV:L), suggesting it may involve local file manipulation or session hijacking that requires a victim to interact with the management console.

Affected products

  • Oracle Corporation WebLogic Server 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle Critical Patch Update published

References

Related threats