SYS::ONLINE
Wasteland.
Briefs1410
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60206 2026-07-21

CVE-2026-60206: Critical SAML Flaw Enables Full Takeover of Oracle WebLogic Server

"A critical, easily exploitable vulnerability in Oracle WebLogic Server allows a low-privileged network attacker to fully compromise the server via SAML, with impacts that can spill over into other products."

A critical, easily exploitable vulnerability in Oracle WebLogic Server allows a low-privileged network attacker to fully compromise the server via SAML, with impacts that can spill over into other products.

What Is It

CVE-2026-60206 is a vulnerability in the Core component of Oracle WebLogic Server, part of Oracle Fusion Middleware. According to Oracle's advisory, an easily exploitable flaw allows a low-privileged attacker with network access via SAML to compromise the server. Successful attacks can result in complete takeover of Oracle WebLogic Server. The vulnerability carries a CVSS 3.1 base score of 9.9 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H.

Why It Matters

The flaw requires only network access and low privileges, with no user interaction, making it straightforward for an authenticated attacker to exploit. It has high confidentiality, integrity, and availability impacts. Critically, the CVSS scope is marked as changed: while the vulnerability resides in Oracle WebLogic Server, Oracle notes that attacks "may significantly impact additional products," meaning a successful compromise can extend beyond WebLogic itself.

What's Vulnerable

The affected product is Oracle WebLogic Server (vendor: Oracle Corporation). The supported versions confirmed as affected are:

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Organizations running affected WebLogic Server versions should apply the fixes referenced in the Oracle Critical Patch Update advisory. No CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed in the provided source material.

Sources