Executive brief
Oracle WebLogic Server, a widely used platform for running enterprise Java applications, contains a security vulnerability in its core component. An attacker with basic user credentials can exploit this flaw over the network to gain full control of the server. This could lead to the theft of sensitive business data, disruption of critical services, and unauthorized access to the broader corporate network.
Technical details
A vulnerability exists in the Core component of Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0. The flaw is categorized as easily exploitable and requires only low-privileged authentication to execute. An attacker can leverage network access via the HTTP protocol to compromise the server environment. Successful exploitation results in a complete takeover of the WebLogic Server, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory