
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-35303 is a missing authentication vulnerability in the Console component of Oracle WebLogic Server, part of Oracle Fusion Middleware. It affects versions 12.2.1.4.0 and 14.1.1.0.0, and was publicly disclosed on June 17, 2026, as part of Oracle's June 2026 Critical Security Patch Update (CSPU). The vulnerability carries a CVSS v3.1 base score of 8.8 (High), reflecting its network-accessible, low-complexity exploitation path requiring only low privileges (Oracle Advisory, NVD).
The vulnerability is classified as CWE-306 (Missing Authentication for Critical Function), meaning a critical function within the WebLogic Server Console component can be accessed or manipulated without adequate authentication checks. An attacker with low-level network access via HTTP can exploit this flaw to compromise the server, suggesting that certain console operations fail to enforce proper authorization controls before execution. No public technical write-ups or proof-of-concept code have been identified at this time. The CAPEC patterns associated with this vulnerability include using unpublished interfaces (CAPEC-36) and cross-site request forgery (CAPEC-62), suggesting the flaw may involve improperly protected administrative endpoints (Oracle Advisory, NVD).
Successful exploitation can result in a full takeover of the affected WebLogic Server, with high impact to confidentiality, integrity, and availability. An attacker could execute arbitrary code, access sensitive application data, modify server configurations, or disrupt service availability. Given WebLogic Server's typical role as a critical application server in enterprise environments, compromise could enable lateral movement into connected backend systems and databases (Oracle Advisory, NVD).
Oracle has released patches for CVE-2026-35303 as part of the June 2026 Critical Security Patch Update. Affected versions are 12.2.1.4.0 and 14.1.1.0.0; administrators should apply the available patches immediately via the Fusion Middleware patch documentation. As a temporary workaround, Oracle recommends restricting HTTP network access to the WebLogic Server Console to trusted systems only and implementing network-level controls to limit exposure. Oracle strongly advises against relying on workarounds as a long-term solution (Oracle Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."