CVE-2026-35301
Oracle WebLogic Server vulnerability analysis and mitigation

Overview

CVE-2026-35301 is a critical missing authentication vulnerability in the Console component of Oracle WebLogic Server, part of Oracle Fusion Middleware. It affects supported versions 12.2.1.4.0 and 14.1.1.0.0, allowing an unauthenticated remote attacker to fully compromise the server via HTTP. The vulnerability was disclosed on June 17, 2026, as part of Oracle's June 2026 Critical Security Patch Update (CSPU). It carries a CVSS v3.1 base score of 10.0 (Critical), with scope change indicating potential impact on additional connected systems (Oracle Advisory, NVD).

Technical details

The root cause is classified as CWE-306 (Missing Authentication for Critical Function), meaning the WebLogic Server Console exposes critical administrative functionality without requiring authentication (NVD). An unauthenticated attacker with network access over HTTP can directly interact with the vulnerable Console component, requiring no privileges and no user interaction. The attack complexity is low and the vulnerability is automatable, making it highly amenable to mass exploitation. The scope change in the CVSS rating indicates that a successful attack can extend beyond the WebLogic Server itself to impact other products or systems in the environment (Oracle Advisory).

Impact

Successful exploitation results in a complete takeover of the affected WebLogic Server, with high impact to confidentiality, integrity, and availability. An attacker can execute arbitrary code, exfiltrate sensitive data, modify application configurations, and disrupt services. Due to the scope change, attacks may significantly impact additional products connected to or dependent on the compromised WebLogic instance, enabling lateral movement within enterprise environments (Oracle Advisory, NVD).

Exploitation steps

  1. Reconnaissance: Use tools such as Shodan or Censys to identify internet-facing Oracle WebLogic Server instances running versions 12.2.1.4.0 or 14.1.1.0.0, specifically looking for exposed HTTP ports (default: 7001) hosting the WebLogic Administration Console.
  2. Identify the Console endpoint: Access the WebLogic Console URL (e.g., http://<target>:7001/console) to confirm the Console component is accessible without authentication.
  3. Exploit missing authentication: Craft HTTP requests targeting the unauthenticated Console functionality. Due to CWE-306, critical administrative functions are accessible without credentials, allowing direct interaction with server management features.
  4. Achieve server takeover: Leverage the unauthenticated access to deploy malicious applications (e.g., WAR/EAR files), modify server configurations, extract credentials or sensitive data, or establish persistent access via a web shell or reverse shell.
  5. Lateral movement: Use the compromised WebLogic Server as a pivot point to access connected systems, databases, or other Oracle Fusion Middleware components within the environment (Oracle Advisory, NVD).

Indicators of compromise

  • Network: Unexpected unauthenticated HTTP requests to the WebLogic Console port (default 7001 or 7002) from external or untrusted IP addresses; unusual outbound connections from the WebLogic server to unknown external hosts.
  • Logs: WebLogic access logs showing unauthenticated access to /console or administrative endpoints without prior authentication events; repeated or automated requests to Console URLs from a single source IP.
  • File System: Unexpected WAR, EAR, or JAR files deployed to the WebLogic deployment directory; new or modified scripts in the WebLogic domain directory; presence of web shells in the application server directories.
  • Process: Unusual child processes spawned by the WebLogic Java process (e.g., cmd.exe, /bin/bash, curl, wget, powershell); unexpected network listeners or services started by the WebLogic service account.

Mitigation and workarounds

Oracle has released patches for CVE-2026-35301 as part of the June 2026 Critical Security Patch Update; affected versions are 12.2.1.4.0 and 14.1.1.0.0, and customers should apply the available patches immediately (Oracle Advisory). As a temporary workaround if patching is delayed, restrict network access to the WebLogic Console port (typically TCP 7001/7002) using firewalls or network segmentation, limiting access to trusted administrative IP ranges only. Oracle strongly recommends customers remain on actively supported versions and apply security patches without delay, as blocking network protocols is not a long-term solution.

Community reactions

The June 2026 Oracle CSPU was noted by security aggregators for containing 245 new security patches, with CVE-2026-35301 highlighted as one of several CVSS 10.0 critical vulnerabilities in Oracle Fusion Middleware (BeyondMachines). Community discussion on platforms such as Bluesky noted the critical nature of the WebLogic Console vulnerability. Security vendors including Qualys and Tenable released detection plugins (Qualys ID 87613, Tenable Nessus plugin 322170) shortly after disclosure, reflecting rapid industry response to the severity of the issue.

Additional resources


SourceThis report was generated using AI

Related Oracle WebLogic Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-60343HIGH8.8
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesJul 21, 2026
CVE-2026-60313HIGH8.8
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesJul 21, 2026
CVE-2026-60528HIGH7.6
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoNoJul 21, 2026
CVE-2026-60529HIGH7.2
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoNoJul 21, 2026
CVE-2026-60527HIGH7.1
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoNoJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management