Junglewise Threat Intelligence

CVE-2026-60528: Oracle WebLogic Server data integrity vulnerability in Console

CVE-2026-60528 · Severity: high · CVSS 7.6 · Published 2026-07-21

Technologies: Oracle WebLogic Server. Vendors: Oracle.

Executive brief

A vulnerability in the Console component of Oracle WebLogic Server allows an authorized administrative user to compromise the system. An attacker could modify or delete critical business data and gain unauthorized access to sensitive information. Because this flaw involves a 'scope change,' an exploit could potentially allow the attacker to move beyond the WebLogic server and impact other connected products and systems.

Technical details

This vulnerability exists in the Console component of Oracle WebLogic Server versions 14.1.2.0.0 and 15.1.1.0.0. It is classified as easily exploitable but requires high privileges (PR:H) to execute via the network over HTTP. The flaw is notable for a 'scope change' (S:C), meaning a successful exploit can impact resources beyond the security scope of the WebLogic Server itself. Attackers can achieve unauthorized creation, deletion, or modification of all accessible data, as well as unauthorized read access to a subset of data. The vulnerability was disclosed as part of the July 2026 Oracle Critical Patch Update.

Affected products

  • Oracle WebLogic Server 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update

References

Related threats