Junglewise Threat Intelligence

CVE-2026-60294: Oracle WebLogic Server remote compromise in Core component

CVE-2026-60294 · Severity: critical · CVSS 9.8 · Published 2026-07-21

Technologies: Oracle WebLogic Server. Vendors: Oracle.

Executive brief

Oracle WebLogic Server, a critical platform for running enterprise business applications, contains a severe security flaw. An unauthorized attacker can remotely take full control of the server over the network without needing a username or password. This could lead to the theft of sensitive data, disruption of business operations, and a complete compromise of the affected infrastructure.

Technical details

A vulnerability in the Core component of Oracle WebLogic Server allows for remote code execution or full system compromise. The flaw is easily exploitable by an unauthenticated attacker with network access via the SOAP protocol. Successful exploitation grants the attacker complete control over the WebLogic Server instance, impacting confidentiality, integrity, and availability. The vulnerability affects supported versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-07-21: advisory: Initial disclosure by Oracle and NVD publication.

References

Related threats