A critical, easily exploitable vulnerability in Oracle WebLogic Server lets an unauthenticated network attacker compromise the server and read or alter all accessible data, carrying a CVSS 3.1 base score of 9.1.
What Is It
CVE-2026-60208 is a vulnerability in the Core component of Oracle WebLogic Server, part of Oracle Fusion Middleware. Per Oracle's advisory, it is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the server. The CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N) reflects network attack vector, low complexity, and no privileges or user interaction required.
Why It Matters
Successful exploitation can result in unauthorized creation, deletion, or modification of critical data, or all WebLogic Server accessible data, as well as unauthorized read access up to complete access of all WebLogic Server accessible data. Because the attack requires no authentication and no user interaction over HTTP, the barrier to exploitation is low. The vulnerability scores 9.1 CRITICAL, with HIGH confidentiality and HIGH integrity impact (availability impact is rated NONE).
What's Vulnerable
Oracle WebLogic Server is affected across the following supported versions:
- 12.2.1.4.0
- 14.1.1.0.0
- 14.1.2.0.0
- 15.1.1.0.0
Patch Status
The vulnerability was published on 2026-07-21 and is addressed in Oracle's July 2026 Critical Patch Update. Administrators should consult the Oracle Critical Patch Update Advisory (July 2026) and apply the corresponding fixes for affected WebLogic Server versions. No CISA KEV entry confirming active exploitation was supplied with this record.
Sources
- Oracle Critical Patch Update Advisory, July 2026, https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60208 (source: [email protected]), published 2026-07-21