CVE-2026-34292: High severity Oracle Oracle WebLogic Server vulnerability
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34292?
CVE-2026-34292 is considered a high severity vulnerability due to its potential for easy exploitation by attackers.
How do I fix CVE-2026-34292?
To mitigate CVE-2026-34292, update your Oracle WebLogic Server to the latest patched version provided by Oracle.
Who is affected by CVE-2026-34292?
CVE-2026-34292 affects Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0.
What type of attack can exploit CVE-2026-34292?
CVE-2026-34292 can be exploited by an attacker with high privileges and network access via HTTP.
What components are involved in CVE-2026-34292?
CVE-2026-34292 involves the Core component of the Oracle WebLogic Server product within Oracle Fusion Middleware.