Executive brief
Oracle WebLogic Server, a widely used application server for hosting enterprise Java applications, contains a critical security flaw in its Core component. An unauthorized attacker can exploit this vulnerability over the network to gain full control of the server. This could lead to the theft of sensitive business data, disruption of critical services, and a total compromise of the application environment.
Technical details
This vulnerability exists in the Core component of Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0. It is classified as an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the server. Successful exploitation results in a complete takeover of the WebLogic Server instance, impacting confidentiality, integrity, and availability. The vulnerability has a CVSS 3.1 base score of 9.8. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0
Timeline
- 2026-07-21: advisory: Initial advisory published by Oracle and NVD.