CVE-2026-35263: Critical severity Oracle WebLogic Server vulnerability
Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebLogic Server. While the vulnerability is in WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of WebLogic Server. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable or restrict HTTP access to the WebLogic Server administrative and application endpoints. If HTTP access is required, bind management interfaces to localhost or internal interfaces and configure ACLs to allow only trusted management IP ranges.
Oracle WebLogic Server HTTP network access / administrative HTTP interfaces = disabled or restricted to trusted IPs - Compensating control
Place network controls in front of WebLogic servers: block or restrict inbound HTTP access at perimeter firewalls, use an internal firewall/ACL to limit access to trusted hosts, and/or deploy a Web Application Firewall (WAF) to filter malicious HTTP requests.
- Operational
Assume potential compromise if public HTTP access existed: isolate suspected hosts from the network, perform incident response and forensic review for indicators of takeover, and rotate any credentials or keys that may have been exposed.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35263?
CVE-2026-35263 has a critical severity rating of 9.9.
How do I fix CVE-2026-35263?
To fix CVE-2026-35263, apply the latest security patches provided by Oracle for affected versions of WebLogic Server.
Which versions are affected by CVE-2026-35263?
The affected versions for CVE-2026-35263 are 14.1.2.0.0 and 15.1.1.0.0 of Oracle WebLogic Server.
What types of attacks can exploit CVE-2026-35263?
CVE-2026-35263 can be exploited by low privileged attackers with network access via HTTP to compromise the WebLogic Server.
What components of Oracle Fusion Middleware are impacted by CVE-2026-35263?
CVE-2026-35263 impacts the Core component of the WebLogic Server product in Oracle Fusion Middleware.