
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-35301 is a critical missing authentication vulnerability in the Console component of Oracle WebLogic Server, part of Oracle Fusion Middleware. It affects supported versions 12.2.1.4.0 and 14.1.1.0.0, allowing an unauthenticated remote attacker to fully compromise the server via HTTP. The vulnerability was disclosed on June 17, 2026, as part of Oracle's June 2026 Critical Security Patch Update (CSPU). It carries a CVSS v3.1 base score of 10.0 (Critical), with scope change indicating potential impact on additional connected systems (Oracle Advisory, NVD).
The root cause is classified as CWE-306 (Missing Authentication for Critical Function), meaning the WebLogic Server Console exposes critical administrative functionality without requiring authentication (NVD). An unauthenticated attacker with network access over HTTP can directly interact with the vulnerable Console component, requiring no privileges and no user interaction. The attack complexity is low and the vulnerability is automatable, making it highly amenable to mass exploitation. The scope change in the CVSS rating indicates that a successful attack can extend beyond the WebLogic Server itself to impact other products or systems in the environment (Oracle Advisory).
Successful exploitation results in a complete takeover of the affected WebLogic Server, with high impact to confidentiality, integrity, and availability. An attacker can execute arbitrary code, exfiltrate sensitive data, modify application configurations, and disrupt services. Due to the scope change, attacks may significantly impact additional products connected to or dependent on the compromised WebLogic instance, enabling lateral movement within enterprise environments (Oracle Advisory, NVD).
http://<target>:7001/console) to confirm the Console component is accessible without authentication./console or administrative endpoints without prior authentication events; repeated or automated requests to Console URLs from a single source IP.cmd.exe, /bin/bash, curl, wget, powershell); unexpected network listeners or services started by the WebLogic service account.Oracle has released patches for CVE-2026-35301 as part of the June 2026 Critical Security Patch Update; affected versions are 12.2.1.4.0 and 14.1.1.0.0, and customers should apply the available patches immediately (Oracle Advisory). As a temporary workaround if patching is delayed, restrict network access to the WebLogic Console port (typically TCP 7001/7002) using firewalls or network segmentation, limiting access to trusted administrative IP ranges only. Oracle strongly recommends customers remain on actively supported versions and apply security patches without delay, as blocking network protocols is not a long-term solution.
The June 2026 Oracle CSPU was noted by security aggregators for containing 245 new security patches, with CVE-2026-35301 highlighted as one of several CVSS 10.0 critical vulnerabilities in Oracle Fusion Middleware (BeyondMachines). Community discussion on platforms such as Bluesky noted the critical nature of the WebLogic Console vulnerability. Security vendors including Qualys and Tenable released detection plugins (Qualys ID 87613, Tenable Nessus plugin 322170) shortly after disclosure, reflecting rapid industry response to the severity of the issue.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."