Unauthenticated Access Vulnerability in Oracle WebLogic Server by Oracle
CVE-2026-60201

8.1HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60201?

The vulnerability within Oracle WebLogic Server affects several versions of Oracle Fusion Middleware. It allows an unauthenticated attacker to gain network access via T3 and IIOP protocols, leading to potential server takeover. This can severely compromise the integrity and confidentiality of the affected systems.

Affected Version(s)

Oracle WebLogic Server 12.2.1.4.0

Oracle WebLogic Server 14.1.1.0.0

Oracle WebLogic Server 14.1.2.0.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.