CVE-2026-34315
Oracle WebLogic Server vulnerability analysis and mitigation

Overview

CVE-2026-34315 is an improper authorization and open redirect vulnerability in the Web Services component of Oracle WebLogic Server, part of Oracle Fusion Middleware. It affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The vulnerability allows unauthenticated remote attackers to compromise the server via HTTP, though successful exploitation requires human interaction from a victim. It was disclosed on April 21, 2026, as part of Oracle's April 2026 Critical Patch Update, and carries a CVSS v3.1 base score of 6.5 (Medium) (Oracle CPU Apr 2026, GitHub Advisory).

Technical details

The vulnerability is classified under CWE-285 (Improper Authorization) and CWE-601 (URL Redirection to Untrusted Site / Open Redirect), as identified by CISA-ADP (GitHub Advisory). The attack vector is network-based over HTTP with low attack complexity and no privileges required, but requires user interaction — consistent with an open redirect scenario where an attacker crafts a malicious URL targeting the WebLogic Web Services component to trick a victim into performing an unintended action. The improper authorization flaw may allow the attacker to bypass access controls and manipulate data accessible to the WebLogic Server. The vulnerability was reported to Oracle by yoloClin of Radiant Security (Oracle CPU Apr 2026). No public proof-of-concept or detailed technical write-up is currently available.

Impact

Successful exploitation results in high integrity impact, enabling unauthorized creation, deletion, or modification of critical data or all Oracle WebLogic Server accessible data. There is no confidentiality or availability impact reported. The scope is unchanged, meaning the impact is confined to the vulnerable WebLogic Server instance itself, though data tampering on a WebLogic Server could affect downstream applications and business processes relying on it (Oracle CPU Apr 2026, GitHub Advisory).

Exploitability

There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at this time (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.027% (8th percentile), indicating a low near-term probability of exploitation. Detection signatures have been added by Qualys (detection IDs 87606, 531206) and Nessus (plugin 309919), enabling scanner-based identification of affected systems (Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Oracle WebLogic Server instances running versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, or 15.1.1.0.0 using tools such as Shodan or Censys, targeting HTTP-accessible Web Services endpoints.
  2. Craft malicious URL: Construct a specially crafted HTTP URL targeting the vulnerable Web Services component of WebLogic Server that exploits the open redirect (CWE-601) or improper authorization (CWE-285) flaw.
  3. Social engineering: Deliver the malicious URL to a legitimate user of the WebLogic Server (e.g., via phishing email or embedded link), inducing them to click it — satisfying the required user interaction condition.
  4. Trigger exploitation: When the victim interacts with the crafted URL, the WebLogic Server processes the request without proper authorization checks, allowing the attacker to perform unauthorized creation, deletion, or modification of critical data accessible to the server.

Note: Specific payload details are not publicly available; the above is based on the vulnerability's CWE classifications and CVSS characteristics (Oracle CPU Apr 2026, GitHub Advisory).

Indicators of compromise

  • Network: Unusual or unexpected HTTP requests to Oracle WebLogic Server Web Services endpoints from external IP addresses; HTTP redirect responses (3xx) to untrusted or external domains originating from the WebLogic server.
  • Logs: WebLogic Server access logs showing requests to Web Services endpoints with suspicious redirect parameters or unexpected referrer headers; authorization-related errors or anomalous access patterns in WebLogic server logs.
  • File System: Unexpected modifications, deletions, or newly created files in directories accessible to the WebLogic Server process following suspicious HTTP activity.
  • Process: Anomalous data modification events in WebLogic-managed data stores or databases shortly after suspicious HTTP requests to Web Services endpoints.

Mitigation and workarounds

Oracle has released patches for all affected versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0) as part of the April 2026 Critical Patch Update; organizations should apply these patches immediately (Oracle CPU Apr 2026). As a temporary workaround, implement network-level controls to restrict HTTP access to WebLogic Server Web Services components to trusted networks only. Additionally, educate users about social engineering attacks, as exploitation requires human interaction. Oracle strongly recommends staying on actively supported versions and applying Critical Patch Updates without delay.

Community reactions

Oracle disclosed this vulnerability as part of its April 2026 Critical Patch Update, which contained 481 new security patches across product families (Oracle CPU Apr 2026). No notable independent researcher commentary, significant social media discussion, or major media coverage specific to CVE-2026-34315 has been identified at this time, consistent with its medium severity rating and lack of public exploit code.

Additional resources


SourceThis report was generated using AI

Related Oracle WebLogic Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-60702CRITICAL9.9
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesAug 18, 2026
CVE-2026-60977CRITICAL9.8
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesAug 18, 2026
CVE-2026-60698CRITICAL9.8
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesAug 18, 2026
CVE-2026-60696CRITICAL9.8
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesAug 18, 2026
CVE-2026-60699HIGH8.6
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management