Exploitable Vulnerability in Oracle Weblogic Server Proxy Plug-in
CVE-2026-60364

9.8CRITICAL

What is CVE-2026-60364?

An exploitable vulnerability exists in the Oracle Weblogic Server Proxy Plug-in, specifically within the Oracle Fusion Middleware. This flaw allows unauthenticated attackers with network access via HTTP to compromise the plug-in, enabling unauthorized creation, deletion, or modification of critical data across the accessible systems. Supported versions affected include 12.2.1.4.0 and 14.1.2.0.0, posing a significant risk to organizations that rely on these versions for their web server integrations.

Affected Version(s)

Oracle HTTP Server 12.2.1.4.0

Oracle HTTP Server 14.1.2.0.0

Oracle Weblogic Server Proxy Plug-in 12.2.1.4.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.