Executive brief
Oracle WebLogic Server, a platform used for building and deploying enterprise Java applications, contains a vulnerability in its Core component. An attacker with low-level user credentials can exploit this flaw over the network to gain full control of the server. This could lead to the theft of sensitive data, disruption of business operations, and unauthorized access to the underlying infrastructure.
Technical details
This vulnerability exists in the Core component of Oracle WebLogic Server. It is classified as easily exploitable, requiring only low-privileged user authentication and network access via the HTTP protocol. A successful exploit allows an attacker to fully compromise the server, impacting confidentiality, integrity, and availability. The vulnerability affects supported versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: advisory: Published by Oracle and NVD