Vulnerability in Oracle WebLogic Server Component of Oracle Fusion Middleware
CVE-2026-60527
7.1HIGH
What is CVE-2026-60527?
A vulnerability exists in the console component of Oracle WebLogic Server within Oracle Fusion Middleware, allowing unauthenticated attackers with logon access to the underlying infrastructure to exploit this weakness. This can lead to unauthorized access to sensitive information or even full control over all data accessible to the WebLogic Server. The risk extends not only to the server itself but can affect additional interconnected products, emphasizing the critical need for prompt mitigation measures. Supported versions impacted include 14.1.2.0.0 and 15.1.1.0.0.
Affected Version(s)
Oracle WebLogic Server 14.1.2.0.0
Oracle WebLogic Server 15.1.1.0.0