Junglewise Threat Intelligence

CVE-2026-83038: Oracle WebLogic Server privilege escalation in TopLink Integration

CVE-2026-83038 · Severity: critical · CVSS 9.9 · Published 2026-09-15

Executive brief

Oracle WebLogic Server is a widely-used application server that hosts enterprise Java applications. This vulnerability in its TopLink Integration component allows a low-privileged authenticated attacker with network access to take complete control of the server, potentially compromising the underlying business applications and data. A successful attack can lead to unauthorized access to sensitive information, data manipulation, and service disruption.

Technical details

This is a privilege escalation vulnerability in the TopLink Integration component of Oracle WebLogic Server. The vulnerability is easily exploitable by a low-privileged attacker with network access via HTTP; no user interaction is required. An authenticated attacker can leverage this flaw to achieve complete compromise of the WebLogic Server instance (confidentiality, integrity, and availability impact), with potential scope change affecting other connected products. The CVSS 3.1 score of 9.9 reflects the severe nature of the vulnerability. Patch availability through Oracle's security updates is expected via standard patch cycles.

Affected products

  • Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: advisory

References

Related threats