CVE-2026-35301: Critical severity Oracle WebLogic Server vulnerability
Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise WebLogic Server. While the vulnerability is in WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of WebLogic Server. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
If the administrative Console is not required, disable it. If it is required, configure the Console to listen only on localhost or a dedicated management network and restrict access to trusted IP addresses.
Oracle WebLogic Server (Console) administrative_console_http_access = disabled or restricted to management network - Compensating control
Restrict network access to the WebLogic Server administrative Console (HTTP). Block or filter HTTP access to affected servers at the network perimeter and internal firewalls/ACLs so only trusted management IPs or networks can reach the Console.
- Compensating control
Place WebLogic Server instances behind a WAF or reverse proxy that can inspect and block malicious HTTP requests and exploit attempts against the Console component.
- Operational
Assume potential compromise if the Console was exposed: isolate affected hosts, perform incident response and forensic investigation, and rotate any credentials or keys that may have been exposed; rebuild or restore systems if compromise is confirmed.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35301?
The severity of CVE-2026-35301 is critical, rated at 10 on the CVSS scale.
How do I fix CVE-2026-35301?
To fix CVE-2026-35301, apply the latest patches released for Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0.
What components are affected by CVE-2026-35301?
CVE-2026-35301 affects the Console component of the Oracle WebLogic Server.
Who can exploit CVE-2026-35301?
CVE-2026-35301 can be exploited by an unauthenticated attacker with network access via HTTP.
What kind of impact does CVE-2026-35301 have?
CVE-2026-35301 can lead to full compromise of the WebLogic Server, impacting confidentiality, integrity, and availability.