Oracle WebLogic Server Vulnerability in Fusion Middleware
CVE-2026-83038

9.9CRITICAL

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-83038?

A vulnerability exists in Oracle WebLogic Server within the Oracle Fusion Middleware suite, specifically in the TopLink Integration component. The supported versions impacted include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. This vulnerability is easily exploitable, allowing an attacker with low privileges and network access via HTTP to take control of the WebLogic Server. Although it primarily affects the WebLogic Server, successful exploitation may have broader ramifications on interconnected systems. Administrators are advised to implement security updates promptly to mitigate potential risks.

Affected Version(s)

Oracle WebLogic Server 12.2.1.4.0

Oracle WebLogic Server 14.1.1.0.0

Oracle WebLogic Server 14.1.2.0.0

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.