Junglewise Threat Intelligence

CVE-2026-60196: Oracle WebLogic Server takeover in Core component

CVE-2026-60196 · Severity: high · CVSS 8.4 · Published 2026-07-21

Technologies: Oracle WebLogic Server. Vendors: Oracle.

Executive brief

Oracle WebLogic Server, a platform used for building and deploying enterprise Java applications, contains a vulnerability in its core component. A high-privileged attacker with access to the local network segment can exploit this flaw to take full control of the server. This could lead to a total loss of data confidentiality and service availability, potentially impacting other integrated business systems.

Technical details

This vulnerability exists in the Core component of Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.2.0.0. It is classified as easily exploitable but requires the attacker to have high privileges and be located on the same physical or logical network segment (Adjacent vector) as the target hardware. Successful exploitation results in a 'scope change,' meaning the attacker can move beyond the WebLogic environment to impact other products. The attack can lead to a complete takeover of the WebLogic Server instance, affecting confidentiality, integrity, and availability. Oracle addressed this in the July 2026 Critical Patch Update.

Affected products

  • Oracle WebLogic Server 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published

References

Related threats