Executive brief
Oracle WebLogic Server, a widely used application server for hosting enterprise Java applications, contains a critical security vulnerability. An unauthorized attacker can remotely take full control of the server over the network without needing a username or password. This could lead to the theft of sensitive data, disruption of business operations, or the use of the server to launch further attacks within the corporate network.
Technical details
This vulnerability exists in the Core component of Oracle WebLogic Server and is exploitable by unauthenticated attackers with network access. The attack vector involves sending specially crafted requests via the T3 or IIOP protocols, which are commonly used for remote administration and communication in WebLogic environments. The flaw is classified as easily exploitable (AC:L) and requires no user interaction. Successful exploitation grants the attacker full control over the WebLogic Server instance, impacting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Users are advised to apply the patches provided in the Oracle Critical Patch Update (CPU) for July 2026.
Affected products
- Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: disclosed: Initial publication of CVE-2026-60202 by Oracle.
- 2026-07-21: advisory: NVD entry created.