Executive brief
Oracle WebLogic Server, a platform used for building and deploying enterprise Java applications, contains a vulnerability that could allow an unauthorized person to take full control of the server. An attacker could potentially steal sensitive data, modify business information, or disrupt critical services. While the attack is difficult to perform, it requires no prior login credentials and can be executed over the network.
Technical details
A vulnerability in the Core component of Oracle WebLogic Server allows unauthenticated attackers with network access via the T3 or IIOP protocols to compromise the system. The vulnerability is classified as difficult to exploit (Attack Complexity: High), but a successful exploit results in a complete takeover of the WebLogic Server instance, impacting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Security administrators should refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation guidance.
Affected products
- Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory