Vulnerability in Oracle WebLogic Server Component of Oracle Fusion Middleware
CVE-2026-60527

7.1HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60527?

A vulnerability exists in the console component of Oracle WebLogic Server within Oracle Fusion Middleware, allowing unauthenticated attackers with logon access to the underlying infrastructure to exploit this weakness. This can lead to unauthorized access to sensitive information or even full control over all data accessible to the WebLogic Server. The risk extends not only to the server itself but can affect additional interconnected products, emphasizing the critical need for prompt mitigation measures. Supported versions impacted include 14.1.2.0.0 and 15.1.1.0.0.

Affected Version(s)

Oracle WebLogic Server 14.1.2.0.0

Oracle WebLogic Server 15.1.1.0.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.