CVE-2026-35302
Oracle WebLogic Server vulnerability analysis and mitigation

Overview

CVE-2026-35302 is an Open Redirect (CWE-601) vulnerability in the Console component of Oracle WebLogic Server, part of Oracle Fusion Middleware. Affected versions are 12.2.1.4.0 and 14.1.1.0.0. The vulnerability was disclosed on June 17, 2026, as part of Oracle's June 2026 Critical Security Patch Update (CSPU). It carries a CVSS v3.1 base score of 8.3 (High), reflecting a network-accessible, unauthenticated attack that requires user interaction and results in a scope change (Oracle CSPU June 2026, NVD).

Technical details

The vulnerability is classified as CWE-601 (URL Redirection to Untrusted Site / Open Redirect) within the WebLogic Server Console component, accessible over HTTP. An unauthenticated remote attacker can craft a malicious URL targeting the WebLogic Console that, when visited by a legitimate user, redirects them to an attacker-controlled site — enabling phishing, credential harvesting, or session token theft. Exploitation requires high attack complexity and human interaction (a victim must follow or be tricked into following the malicious link), but no privileges are required on the part of the attacker. The scope change indicator suggests that successful exploitation can impact systems beyond the WebLogic Server itself (Oracle CSPU June 2026, NVD).

Impact

Successful exploitation can result in complete takeover of the WebLogic Server, with high impacts to confidentiality, integrity, and availability. Because the vulnerability involves a scope change, additional products connected to or dependent on the WebLogic Server may also be significantly impacted. In practice, an open redirect in the WebLogic Console can be leveraged to steal administrator credentials or session tokens via phishing, potentially enabling an attacker to gain full administrative control over the server and its managed applications (Oracle CSPU June 2026, NVD).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Oracle WebLogic Server instances running versions 12.2.1.4.0 or 14.1.1.0.0 using tools such as Shodan or Censys, focusing on exposed HTTP ports associated with the WebLogic Administration Console (typically port 7001 or 7002).
  2. Craft malicious redirect URL: Construct a URL targeting the vulnerable WebLogic Console endpoint that includes a redirect parameter pointing to an attacker-controlled domain (e.g., http://<target>:7001/console/login/LoginForm.jsp?redirect=https://attacker.com/phish).
  3. Social engineering: Deliver the crafted URL to a legitimate WebLogic administrator or user via phishing email, instant message, or other social engineering vector, enticing them to click the link.
  4. Credential/session harvesting: When the victim clicks the link and is redirected to the attacker's site, capture submitted credentials, session tokens, or other sensitive information via a spoofed login page.
  5. Leverage access: Use harvested credentials or session tokens to authenticate to the WebLogic Console and achieve full administrative control, enabling further lateral movement, data exfiltration, or deployment of malicious applications (Oracle CSPU June 2026, NVD).

Indicators of compromise

  • Network: HTTP requests to the WebLogic Console (ports 7001/7002) containing suspicious redirect parameters pointing to external or unknown domains; outbound HTTP/HTTPS connections from the WebLogic server to unfamiliar external hosts following console access.
  • Logs: WebLogic access logs showing requests to console login endpoints (e.g., /console/login/LoginForm.jsp) with unusual or external redirect query parameters; authentication events from unexpected IP addresses or geographic locations in WebLogic audit logs.
  • File System: Unexpected new application deployments (WAR/EAR files) in the WebLogic deployment directories following a potential compromise of admin credentials.
  • Process: Unusual child processes spawned by the WebLogic JVM process after a suspected credential compromise, such as shell commands or network utilities.

Mitigation and workarounds

Oracle has released patches for CVE-2026-35302 as part of the June 2026 Critical Security Patch Update (CSPU); customers should apply the relevant patches for WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0 immediately via the Fusion Middleware patch documentation. As a temporary workaround, restrict HTTP/HTTPS access to the WebLogic Administration Console to trusted internal networks and IP addresses only, reducing the attack surface. Additionally, implement strong authentication controls for console access, educate administrators about phishing and social engineering risks, and monitor console access logs for anomalous redirect parameters or login attempts from unexpected sources (Oracle CSPU June 2026).

Community reactions

Oracle's June 2026 CSPU advisory notes the vulnerability and strongly recommends customers apply patches without delay, citing ongoing reports of attackers exploiting unpatched Oracle systems. No notable independent researcher commentary, social media discussion, or significant media coverage specific to CVE-2026-35302 has been identified at this time, likely due to the absence of public exploit code and the requirement for user interaction (Oracle CSPU June 2026).

Additional resources


SourceThis report was generated using AI

Related Oracle WebLogic Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-60343HIGH8.8
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesJul 21, 2026
CVE-2026-60313HIGH8.8
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesJul 21, 2026
CVE-2026-60528HIGH7.6
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoNoJul 21, 2026
CVE-2026-60529HIGH7.2
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoNoJul 21, 2026
CVE-2026-60527HIGH7.1
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoNoJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management