CVE-2026-60206
Published Jul 21, 2026
Last updated a month ago
AI description
CVE-2026-60206 is a vulnerability found in the Core component of Oracle WebLogic Server, part of Oracle Fusion Middleware. This easily exploitable flaw allows a low-privileged attacker with network access, specifically via SAML, to compromise the Oracle WebLogic Server. Successful exploitation of this vulnerability can lead to a complete takeover of the Oracle WebLogic Server. Furthermore, while the vulnerability resides within WebLogic Server, attacks may significantly impact additional products due to a "scope change." Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
- Description
- Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SAML to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
- Source
- secalert_us@oracle.com
- NVD status
- Analyzed
- Products
- weblogic_server
CVSS 3.1
- Type
- Secondary
- Base score
- 9.9
- Impact score
- 6
- Exploitability score
- 3.1
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-306
- Hype score
- Not currently trending
CVE-2026-60206 | CVSS 9.9 Oracle WebLogic SAML Auth Bypass PoC https://t.co/IqUgdjPdr1
@st8less
2 Aug 2026
1007 Impressions
4 Retweets
20 Likes
11 Bookmarks
0 Replies
0 Quotes
Warning: Multiple (100+) vulnerabilities in #Oracle #WebLogic Server Fusion Middleware. #CVE-2026-60206 #CVE-2026-61211 #CVE-2026-47040 #CVE-2026-4738. There are publicly available proof-of-concepts #PoC See advisory https://t.co/oDqrI3ifSg #Patch #Patch #Patch
@CCBalert
31 Jul 2026
270 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
🚨 CVE-2026-60206: Oracle WebLogic Server Arbitrary File Read Critical Vulnerability Alert! Oracle WebLogic is affected by CVE-2026-60206. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://t.co/djl120dim1 🔍 Identify Targets via ZoomEye: Filter: https://t
@zoomeye_team
23 Jul 2026
8605 Impressions
30 Retweets
98 Likes
40 Bookmarks
2 Replies
1 Quote
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*",
"matchCriteriaId": "4A5BB153-68E0-4DDA-87D1-0D9AB7F0A418",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*",
"matchCriteriaId": "04BCDC24-4A21-473C-8733-0D9CFB38A752",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:oracle:weblogic_server:14.1.2.0.0:*:*:*:*:*:*:*",
"matchCriteriaId": "0FCA3D99-4596-4CF0-B5E1-7A6497F83B83",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:oracle:weblogic_server:15.1.1.0.0:*:*:*:*:*:*:*",
"matchCriteriaId": "F538D9B4-B101-4182-8C69-F30B183DD3A2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]