
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-35302 is an Open Redirect (CWE-601) vulnerability in the Console component of Oracle WebLogic Server, part of Oracle Fusion Middleware. Affected versions are 12.2.1.4.0 and 14.1.1.0.0. The vulnerability was disclosed on June 17, 2026, as part of Oracle's June 2026 Critical Security Patch Update (CSPU). It carries a CVSS v3.1 base score of 8.3 (High), reflecting a network-accessible, unauthenticated attack that requires user interaction and results in a scope change (Oracle CSPU June 2026, NVD).
The vulnerability is classified as CWE-601 (URL Redirection to Untrusted Site / Open Redirect) within the WebLogic Server Console component, accessible over HTTP. An unauthenticated remote attacker can craft a malicious URL targeting the WebLogic Console that, when visited by a legitimate user, redirects them to an attacker-controlled site — enabling phishing, credential harvesting, or session token theft. Exploitation requires high attack complexity and human interaction (a victim must follow or be tricked into following the malicious link), but no privileges are required on the part of the attacker. The scope change indicator suggests that successful exploitation can impact systems beyond the WebLogic Server itself (Oracle CSPU June 2026, NVD).
Successful exploitation can result in complete takeover of the WebLogic Server, with high impacts to confidentiality, integrity, and availability. Because the vulnerability involves a scope change, additional products connected to or dependent on the WebLogic Server may also be significantly impacted. In practice, an open redirect in the WebLogic Console can be leveraged to steal administrator credentials or session tokens via phishing, potentially enabling an attacker to gain full administrative control over the server and its managed applications (Oracle CSPU June 2026, NVD).
http://<target>:7001/console/login/LoginForm.jsp?redirect=https://attacker.com/phish)./console/login/LoginForm.jsp) with unusual or external redirect query parameters; authentication events from unexpected IP addresses or geographic locations in WebLogic audit logs.Oracle has released patches for CVE-2026-35302 as part of the June 2026 Critical Security Patch Update (CSPU); customers should apply the relevant patches for WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0 immediately via the Fusion Middleware patch documentation. As a temporary workaround, restrict HTTP/HTTPS access to the WebLogic Administration Console to trusted internal networks and IP addresses only, reducing the attack surface. Additionally, implement strong authentication controls for console access, educate administrators about phishing and social engineering risks, and monitor console access logs for anomalous redirect parameters or login attempts from unexpected sources (Oracle CSPU June 2026).
Oracle's June 2026 CSPU advisory notes the vulnerability and strongly recommends customers apply patches without delay, citing ongoing reports of attackers exploiting unpatched Oracle systems. No notable independent researcher commentary, social media discussion, or significant media coverage specific to CVE-2026-35302 has been identified at this time, likely due to the absence of public exploit code and the requirement for user interaction (Oracle CSPU June 2026).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."