Vulnerability in Oracle WebLogic Server Affects Fusion Middleware
CVE-2026-60291
What is CVE-2026-60291?
CVE-2026-60291 is a high-severity vulnerability affecting Oracle WebLogic Server, a core component of Oracle Fusion Middleware. This software is designed to facilitate the integration and management of business applications, making it essential for many organizations that rely on Oracle technologies. The vulnerability allows unauthenticated attackers with network access via HTTP to exploit the server, potentially compromising its integrity and availability. With a CVSS 3.1 base score of 9.8, this vulnerability represents a critical risk, as successful exploitation can result in complete takeover of the WebLogic Server, leading to severe consequences for organizations' operations and data security.
Potential impact of CVE-2026-60291
-
Complete System Compromise: The vulnerability allows attackers to gain unrestricted access, which could lead to full control over the affected WebLogic Server, enabling them to manipulate or exfiltrate sensitive data stored within the system.
-
Damage to Confidentiality, Integrity, and Availability: Given its high CVSS score, this vulnerability can severely impact the confidentiality, integrity, and availability of data and services. Attackers could alter, corrupt, or delete critical data, causing operational disruptions.
-
Increased Risk of Further Attacks: Once compromised, the WebLogic Server could serve as a stepping stone for attackers to launch additional attacks on other systems within the organization's network, expanding the overall threat landscape and putting more resources at risk.
Affected Version(s)
Oracle WebLogic Server 12.2.1.4.0
Oracle WebLogic Server 14.1.1.0.0
Oracle WebLogic Server 14.1.2.0.0