Executive brief
Oracle WebLogic Server, a critical platform for running enterprise Java applications, contains a vulnerability that allows an attacker to take full control of the server. An individual with low-level access to the network can exploit this flaw through the system's identity management component. A successful attack could lead to the theft of sensitive data, disruption of business operations, and potential unauthorized access to other connected corporate systems.
Technical details
A critical vulnerability exists in the Core component of Oracle WebLogic Server (versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0). The flaw is easily exploitable by a low-privileged attacker with network access via the Security Assertion Markup Language (SAML) protocol. The vulnerability is characterized by a 'scope change' (Status: Changed in CVSS), meaning a successful exploit can impact components beyond the WebLogic Server itself. Attackers can achieve complete takeover of the server, resulting in high impacts on confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD published the CVE record