Junglewise Threat Intelligence

CVE-2026-60313: Oracle WebLogic Server takeover via RMI in Core component

CVE-2026-60313 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle WebLogic Server. Vendors: Oracle.

Executive brief

Oracle WebLogic Server, a widely used platform for running enterprise Java applications, contains a security vulnerability in its core component. An attacker with basic user credentials can exploit this flaw over the network to take full control of the server. This could lead to the theft of sensitive business data, unauthorized modification of applications, or a complete shutdown of critical services.

Technical details

A vulnerability in the Core component of Oracle WebLogic Server allows for unauthorized takeover of the application environment. The flaw is exploitable by a low-privileged attacker with network access via the Remote Method Invocation (RMI) protocol. The vulnerability is characterized by low attack complexity and requires no user interaction, though it does require valid (low-level) authentication. Successful exploitation results in high impacts to confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-60313

References

Related threats