Junglewise Threat Intelligence

CVE-2026-60312: Oracle WebLogic Server remote compromise in Core component

CVE-2026-60312 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle WebLogic Server. Vendors: Oracle.

Executive brief

Oracle WebLogic Server, a platform used for building and deploying enterprise applications, contains a vulnerability that could allow an unauthorized person to take full control of the server. An attacker could use this access to steal sensitive data, disrupt business operations, or use the server as a foothold for further attacks. While the attack is difficult to perform, it requires no user interaction and can be executed over the network.

Technical details

A vulnerability in the Core component of Oracle WebLogic Server allows unauthenticated attackers with network access via the T3 or IIOP protocols to compromise the system. The vulnerability is classified as difficult to exploit (High Attack Complexity) but can result in a complete takeover of the server, impacting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Attackers do not require prior privileges or user interaction to execute the exploit. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-60312

References

Related threats