CVE-2026-35259: High severity Oracle WebLogic Server vulnerability
Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise WebLogic Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of WebLogic Server. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
If the WebLogic Server Console is not required, disable Console access over HTTPS to remove the exposed component.
Oracle WebLogic Server (Console) Console HTTPS access = disabled if not required - Compensating control
Restrict network access to the WebLogic Server Console (HTTPS) to trusted IP addresses or internal networks via firewall/ACL/WAF; block or deny HTTPS access from the public Internet.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35259?
The severity of CVE-2026-35259 is rated as high with a score of 8.8.
How do I fix CVE-2026-35259?
To fix CVE-2026-35259, upgrade to the latest supported version of Oracle WebLogic Server that addresses this vulnerability.
Who is affected by CVE-2026-35259?
CVE-2026-35259 affects Oracle WebLogic Server versions 14.1.2.0.0 and 15.1.1.0.0.
Can CVE-2026-35259 be exploited remotely?
Yes, CVE-2026-35259 can be exploited remotely by an unauthenticated attacker with network access via HTTPS.
What impact does CVE-2026-35259 have on the system?
The impact of CVE-2026-35259 includes potential compromise of the WebLogic Server and a breach of confidentiality, integrity, and availability.