Unauthenticated Access Vulnerability in Oracle WebLogic Server by Oracle
CVE-2026-60699

8.6HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-60699?

A vulnerability exists in Oracle WebLogic Server that enables an unauthenticated attacker to compromise the system through network access methods such as T3 and IIOP. This severe weakness affects specific versions of the server, opening the door to unauthorized access and potential exposure of sensitive data. Although primarily impacting WebLogic Server, the repercussions could extend to other integrated products, significantly increasing the risk of data breaches and unauthorized data access.

Affected Version(s)

Oracle WebLogic Server 12.2.1.4.0

Oracle WebLogic Server 14.1.1.0.0

Oracle WebLogic Server 14.1.2.0.0

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.