PT-2026-49872 · Oracle · Oracle Weblogic Server
CVE-2026-35301
·
Published
2026-06-16
·
Updated
2026-06-18
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Oracle WebLogic Server version 12.2.1.4.0
Oracle WebLogic Server version 14.1.1.0.0
Description
An issue exists in the Console component of Oracle Fusion Middleware WebLogic Server. This flaw allows an unauthenticated attacker with network access via HTTP to achieve remote code execution, potentially leading to a full takeover of the server. The impact may extend beyond the WebLogic Server to other integrated products.
Recommendations
Apply the available patch for version 12.2.1.4.0.
Apply the available patch for version 14.1.1.0.0.
Fix
RCE
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oracle Weblogic Server