CVE-2026-60679: High severity Oracle Oracle WebLogic Server vulnerability
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Oracle WebLogic Server deployments running versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, or 15.1.1.0.0 are affected if an attacker with low privileges can reach the server over T3 or IIOP.
What does an attacker need to exploit it?
An attacker needs network access through T3 or IIOP and an existing low-privileged account or access level. No user interaction is required, but exploitation is described as difficult.
What is the potential impact of successful exploitation?
A successful attack can result in takeover of Oracle WebLogic Server, with high impacts to confidentiality, integrity, and availability.