PT-2026-49872 · Oracle · Oracle Weblogic Server

CVE-2026-35301

·

Published

2026-06-16

·

Updated

2026-06-18

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Oracle WebLogic Server version 12.2.1.4.0 Oracle WebLogic Server version 14.1.1.0.0
Description An issue exists in the Console component of Oracle Fusion Middleware WebLogic Server. This flaw allows an unauthenticated attacker with network access via HTTP to achieve remote code execution, potentially leading to a full takeover of the server. The impact may extend beyond the WebLogic Server to other integrated products.
Recommendations Apply the available patch for version 12.2.1.4.0. Apply the available patch for version 14.1.1.0.0.

Fix

RCE

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35301

Affected Products

Oracle Weblogic Server