CVE-2026-60207: High severity Oracle Oracle WebLogic Server vulnerability
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60207?
The severity of CVE-2026-60207 is high, with a score of 8.8.
What versions of Oracle WebLogic Server are affected by CVE-2026-60207?
The affected versions of Oracle WebLogic Server are 12.2.1.4.0 and 14.1.2.0.0.
How can an attacker exploit CVE-2026-60207?
An attacker can exploit CVE-2026-60207 by using a network access via HTTP with low privileges.
What is the impact of exploiting CVE-2026-60207?
Exploiting CVE-2026-60207 can allow an attacker to compromise the Oracle WebLogic Server.
How do I fix CVE-2026-60207?
To fix CVE-2026-60207, Oracle recommends applying the latest patches provided for affected versions of WebLogic Server.