Junglewise Threat Intelligence

CVE-2026-60153: Oracle WebLogic Server compromise in Console

CVE-2026-60153 · Severity: high · CVSS 7.2 · Published 2026-07-21

Technologies: Oracle WebLogic Server. Vendors: Oracle.

Executive brief

A vulnerability in the Console component of Oracle WebLogic Server allows a high-privileged user to take full control of the server. WebLogic is a critical application server used to run enterprise business applications; a successful compromise could lead to a total loss of data confidentiality and service availability. This issue affects several supported versions and can be exploited over the network via HTTPS.

Technical details

This vulnerability exists in the Console component of Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. It is classified as an easily exploitable flaw that allows a high-privileged attacker with network access via HTTPS to compromise the server. Successful exploitation can result in a complete takeover of the WebLogic Server instance, impacting confidentiality, integrity, and availability. The vulnerability is tracked as part of the Oracle July 2026 Critical Patch Update. Attackers require high privileges (PR:H) to execute the exploit, but no user interaction is required.

Affected products

  • Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-60153
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released

References

Related threats