Executive brief
Oracle WebLogic Server, a widely used application server for hosting enterprise Java applications, contains a high-severity vulnerability in its Core component. An attacker with low-level user credentials can exploit this flaw over the network to gain full control of the server. This could lead to the theft of sensitive business data, unauthorized modification of applications, or a complete shutdown of critical services.
Technical details
A vulnerability exists in the Core component of Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.2.0.0. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows for a complete takeover of the WebLogic Server instance, impacting confidentiality, integrity, and availability. The attack vector is remote and does not require user interaction, though it does require basic authentication (PR:L). Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle WebLogic Server 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: advisory: Initial disclosure by Oracle and NVD publication.