Executive brief
Oracle WebLogic Server, a critical platform for running enterprise Java applications, contains a severe vulnerability in its core component. An unauthorized attacker can remotely take full control of the server over the network without needing any login credentials. This could lead to a total loss of data confidentiality, system integrity, and service availability, potentially allowing attackers to steal sensitive information or disrupt business operations.
Technical details
This vulnerability exists in the Core component of Oracle WebLogic Server and is characterized by its ease of exploitation. An unauthenticated attacker can achieve remote code execution or full system takeover by sending specially crafted requests over the T3 or IIOP protocols. The flaw affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The attack vector is network-based and requires no user interaction or prior privileges. Organizations are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory