Executive brief
Oracle WebLogic Server, a widely used platform for running enterprise Java applications, contains a critical security flaw. An unauthorized attacker can remotely take full control of the server over the network without needing a username or password. This could lead to the theft of sensitive data, disruption of business operations, or a complete system takeover.
Technical details
A critical vulnerability exists in the Core component of Oracle WebLogic Server. The flaw is easily exploitable by an unauthenticated attacker with network access via the T3 or IIOP protocols. It does not require user interaction and has a low attack complexity. Successful exploitation allows for a complete takeover of the WebLogic Server instance, impacting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: advisory: Initial advisory published by Oracle and NVD.