Executive brief
Oracle WebLogic Server, a widely used application server for hosting enterprise Java applications, contains a critical security vulnerability in its core component. An unauthorized attacker can exploit this flaw over the network without any valid credentials or user interaction. A successful attack could lead to a complete takeover of the server, potentially resulting in the theft of sensitive data, disruption of business operations, or further unauthorized access to the corporate network.
Technical details
This vulnerability exists in the Core component of Oracle WebLogic Server and is characterized by its ease of exploitation. It allows an unauthenticated attacker with network access via HTTP to compromise the server environment. The vulnerability has a CVSS 3.1 base score of 9.8, indicating high impacts on confidentiality, integrity, and availability. While the specific vulnerability class (e.g., RCE, deserialization) is not explicitly named in the summary, the 'takeover' impact and network vector suggest a critical remote code execution or authentication bypass flaw. Organizations should refer to the Oracle July 2026 Critical Patch Update for remediation steps.
Affected products
- Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: disclosed: Initial publication of CVE-2026-60291
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released