A critical, unauthenticated remote vulnerability in Oracle WebLogic Server allows a network attacker to fully compromise and take over affected servers over HTTP.
What Is It
CVE-2026-60291 is a critical vulnerability in the Core component of Oracle WebLogic Server, part of Oracle Fusion Middleware. Per Oracle's advisory, it is an "easily exploitable" flaw that allows an unauthenticated attacker with network access via HTTP to compromise the server. Successful exploitation can result in complete takeover of Oracle WebLogic Server. It carries a CVSS 3.1 base score of 9.8 (CRITICAL), with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, meaning no authentication, no user interaction, and low attack complexity, with high impact to confidentiality, integrity, and availability.
Why It Matters
The combination of network reachability, no required privileges or user interaction, and full server takeover makes this among the most severe classes of vulnerability. WebLogic servers frequently sit on internet-facing infrastructure and host business-critical middleware, so a flaw that hands an unauthenticated attacker complete control is high-value for opportunistic and targeted attackers alike. The 3.9 exploitability sub-score reflects how readily this can be attacked.
What's Vulnerable
The affected product is Oracle WebLogic Server (Oracle Fusion Middleware, Core component). Supported versions listed as affected:
- 12.2.1.4.0
- 14.1.1.0.0
- 14.1.2.0.0
- 15.1.1.0.0
Patch Status
Oracle addressed this vulnerability in its July 2026 Critical Patch Update (CPU). Organizations running any affected version should apply the fixes referenced in the Oracle July 2026 CPU advisory. No CISA KEV entry accompanied this source material, so active exploitation is not confirmed in the supplied data; given the 9.8 severity and unauthenticated network vector, patching should be prioritized regardless.
Sources
- Oracle Critical Patch Update Advisory, July 2026, https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60291, https://nvd.nist.gov/vuln/detail/CVE-2026-60291