Junglewise Threat Intelligence

CVE-2026-60364: Oracle Weblogic Server Proxy Plug-in integrity compromise

CVE-2026-60364 · Severity: critical · CVSS 9.8 · Published 2026-07-21

Executive brief

A vulnerability exists in the Oracle WebLogic Server Proxy Plug-in, a component used to connect third-party web servers like Apache or IIS to WebLogic application servers. An unauthenticated attacker can exploit this over the network to gain unauthorized access to system data. This could lead to the unauthorized creation, deletion, or modification of critical business information, potentially compromising the integrity of the entire application environment.

Technical details

This vulnerability affects the WebLogic Server Proxy Plug-in for Third-Party Web Servers within Oracle Fusion Middleware. The flaw is categorized as easily exploitable and requires no authentication or user interaction (AV:N/AC:L/PR:N/UI:N). While the initial description suggests an integrity-only impact (CVSS 7.5), the official Oracle CNA assessment rates it as a 9.8, indicating high impacts to confidentiality, integrity, and availability. Attackers can leverage HTTP requests to gain unauthorized access to create, delete, or modify all data accessible by the plug-in. Affected versions include 12.2.1.4.0 and 14.1.2.0.0.

Affected products

  • Oracle Weblogic Server Proxy Plug-in 12.2.1.4.0, 14.1.2.0.0
  • Oracle Oracle HTTP Server 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: advisory: Published by Oracle in the July 2026 Critical Patch Update

References

Related threats