Junglewise Threat Intelligence

CVE-2026-60527: Oracle WebLogic Server information disclosure in Console

CVE-2026-60527 · Severity: high · CVSS 7.1 · Published 2026-07-21

Technologies: Oracle WebLogic Server. Vendors: Oracle.

Executive brief

A vulnerability exists in the Console component of Oracle WebLogic Server, a platform used for building and deploying enterprise applications. An attacker who has already gained access to the underlying server infrastructure can exploit this flaw to gain unauthorized access to sensitive data. This could lead to a significant breach of confidentiality and potentially impact other integrated business systems.

Technical details

This vulnerability affects the Console component of Oracle WebLogic Server versions 14.1.2.0.0 and 15.1.1.0.0. It is classified as an information disclosure flaw that is easily exploitable by an unauthenticated attacker who has already obtained logon access to the infrastructure where the server executes (Local attack vector). The exploit results in a scope change (S:C), meaning the impact can extend beyond the WebLogic Server itself to other products. Successful exploitation allows for unauthorized access to critical data or complete access to all data accessible by the WebLogic Server. The vulnerability was disclosed as part of the Oracle July 2026 Critical Patch Update.

Affected products

  • Oracle WebLogic Server 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-60527
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released

References

Related threats