
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34315 is an improper authorization and open redirect vulnerability in the Web Services component of Oracle WebLogic Server, part of Oracle Fusion Middleware. It affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The vulnerability allows unauthenticated remote attackers to compromise the server via HTTP, though successful exploitation requires human interaction from a victim. It was disclosed on April 21, 2026, as part of Oracle's April 2026 Critical Patch Update, and carries a CVSS v3.1 base score of 6.5 (Medium) (Oracle CPU Apr 2026, GitHub Advisory).
The vulnerability is classified under CWE-285 (Improper Authorization) and CWE-601 (URL Redirection to Untrusted Site / Open Redirect), as identified by CISA-ADP (GitHub Advisory). The attack vector is network-based over HTTP with low attack complexity and no privileges required, but requires user interaction — consistent with an open redirect scenario where an attacker crafts a malicious URL targeting the WebLogic Web Services component to trick a victim into performing an unintended action. The improper authorization flaw may allow the attacker to bypass access controls and manipulate data accessible to the WebLogic Server. The vulnerability was reported to Oracle by yoloClin of Radiant Security (Oracle CPU Apr 2026). No public proof-of-concept or detailed technical write-up is currently available.
Successful exploitation results in high integrity impact, enabling unauthorized creation, deletion, or modification of critical data or all Oracle WebLogic Server accessible data. There is no confidentiality or availability impact reported. The scope is unchanged, meaning the impact is confined to the vulnerable WebLogic Server instance itself, though data tampering on a WebLogic Server could affect downstream applications and business processes relying on it (Oracle CPU Apr 2026, GitHub Advisory).
There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at this time (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.027% (8th percentile), indicating a low near-term probability of exploitation. Detection signatures have been added by Qualys (detection IDs 87606, 531206) and Nessus (plugin 309919), enabling scanner-based identification of affected systems (Feedly).
Note: Specific payload details are not publicly available; the above is based on the vulnerability's CWE classifications and CVSS characteristics (Oracle CPU Apr 2026, GitHub Advisory).
Oracle has released patches for all affected versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0) as part of the April 2026 Critical Patch Update; organizations should apply these patches immediately (Oracle CPU Apr 2026). As a temporary workaround, implement network-level controls to restrict HTTP access to WebLogic Server Web Services components to trusted networks only. Additionally, educate users about social engineering attacks, as exploitation requires human interaction. Oracle strongly recommends staying on actively supported versions and applying Critical Patch Updates without delay.
Oracle disclosed this vulnerability as part of its April 2026 Critical Patch Update, which contained 481 new security patches across product families (Oracle CPU Apr 2026). No notable independent researcher commentary, significant social media discussion, or major media coverage specific to CVE-2026-34315 has been identified at this time, consistent with its medium severity rating and lack of public exploit code.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."