Unauthenticated Access Vulnerability in Oracle WebLogic Server by Oracle
CVE-2026-60198
9.8CRITICAL
What is CVE-2026-60198?
A vulnerability exists in the Oracle WebLogic Server that allows an unauthenticated attacker with network access through T3 or IIOP protocols to potentially compromise the server. This security flaw could lead to complete takeover of the affected Oracle WebLogic Server instances, impacting confidentiality, integrity, and availability of sensitive information and services.
Affected Version(s)
Oracle WebLogic Server 12.2.1.4.0
Oracle WebLogic Server 14.1.1.0.0
Oracle WebLogic Server 14.1.2.0.0