CVE-2026-60529: High severity Oracle Oracle WebLogic Server vulnerability
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle WebLogic Server (Oracle Fusion Middleware) - Consoleto a version that resolves this vulnerability.Fixed in 14.1.2.0.0 - Upgrade
Upgrade
Oracle WebLogic Server (Oracle Fusion Middleware) - Consoleto a version that resolves this vulnerability.Fixed in 15.1.1.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60529?
CVE-2026-60529 has a severity rating of high at 7.2.
How do I fix CVE-2026-60529?
To fix CVE-2026-60529, upgrade to the latest supported versions of Oracle WebLogic Server that are no longer affected.
What products are affected by CVE-2026-60529?
CVE-2026-60529 affects the Oracle WebLogic Server product versions 14.1.2.0.0 and 15.1.1.0.0.
What type of access is required to exploit CVE-2026-60529?
CVE-2026-60529 can be exploited by a high privileged attacker with network access via HTTP.
What are the potential impacts of CVE-2026-60529?
CVE-2026-60529 allows an attacker to compromise confidentiality, integrity, and availability of the Oracle WebLogic Server.