Vulnerability in Oracle WebLogic Server Component of Oracle Fusion Middleware
CVE-2026-60528

7.6HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60528?

This vulnerability affects Oracle WebLogic Server, allowing an attacker with high privileges and network access to exploit the system via HTTP. The impact can lead to unauthorized creation, deletion, or modification of critical data within Oracle WebLogic Server. Furthermore, it may also enable unauthorized read access to a subset of accessible data. Given the interconnected nature of the impacted product, successful exploitation could also affect additional products connected to Oracle WebLogic Server, highlighting the broad scope of this security risk.

Affected Version(s)

Oracle WebLogic Server 14.1.2.0.0

Oracle WebLogic Server 15.1.1.0.0

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.