CVE-2026-60206

Published Jul 21, 2026

Last updated a month ago

CVSS critical 9.9
Oracle WebLogic Server
Oracle Fusion Middleware

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-60206 is a vulnerability found in the Core component of Oracle WebLogic Server, part of Oracle Fusion Middleware. This easily exploitable flaw allows a low-privileged attacker with network access, specifically via SAML, to compromise the Oracle WebLogic Server. Successful exploitation of this vulnerability can lead to a complete takeover of the Oracle WebLogic Server. Furthermore, while the vulnerability resides within WebLogic Server, attacks may significantly impact additional products due to a "scope change." Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.

Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SAML to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Source
secalert_us@oracle.com
NVD status
Analyzed
Products
weblogic_server

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.9
Impact score
6
Exploitability score
3.1
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-306

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.