Junglewise Threat Intelligence

CVE-2026-60529: Oracle WebLogic Server compromise in Console component

CVE-2026-60529 · Severity: high · CVSS 7.2 · Published 2026-07-21

Executive brief

Oracle WebLogic Server, a widely used application server for hosting enterprise Java applications, contains a vulnerability in its management console. A high-privileged attacker could exploit this flaw to gain full control over the server, potentially leading to the theft of sensitive data or a complete disruption of business operations. Organizations using affected versions should apply the latest security updates from Oracle immediately.

Technical details

This vulnerability exists in the Console component of Oracle WebLogic Server versions 14.1.2.0.0 and 15.1.1.0.0. It is classified as easily exploitable, requiring network access via HTTP. While the specific vulnerability class (e.g., RCE, injection) is not explicitly named in the advisory, the impact is a complete compromise of Confidentiality, Integrity, and Availability (takeover). The attack requires high privileges (PR:H), meaning the attacker must already have administrative-level access to the console to execute the exploit. Oracle has addressed this in the July 2026 Critical Patch Update.

Affected products

  • Oracle WebLogic Server 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle Critical Patch Update published

References

Related threats