CVE-2026-60364
Weblogic Server Proxy Plug-in for Apache HTTP Server vulnerability analysis and mitigation

Overview

CVE-2026-60364 is an Improper Access Control vulnerability (CWE-284) in the Oracle WebLogic Server Proxy Plug-In for Third-Party Web Servers, a component of Oracle Fusion Middleware. It affects versions 12.2.1.4.0 and 14.1.2.0.0 of both Oracle WebLogic Server Proxy Plug-in and Oracle HTTP Server. The vulnerability was published on July 21, 2026, as part of Oracle's July 2026 Critical Patch Update. Feedly threat intelligence data assigns a CVSS v3.1 base score of 9.8 (Critical), while Oracle's official advisory description references a score of 7.5 (High) focused on integrity impacts — the higher score reflects the full CIA impact assessed by Feedly/ENISA (Oracle CPU Jul 2026).

Technical details

The vulnerability is classified as CWE-284 (Improper Access Control), meaning the proxy plug-in component fails to properly enforce access restrictions on incoming HTTP requests. An unauthenticated attacker with network access via HTTP can exploit this flaw without any privileges or user interaction, making it highly automatable. The attack vector is entirely network-based and requires low complexity, targeting the WebLogic Server Proxy Plug-In interface used to connect third-party web servers (e.g., Apache HTTP Server, IIS) to WebLogic backends. No public proof-of-concept or detailed technical write-up has been identified at this time (Oracle CPU Jul 2026).

Impact

Successful exploitation allows an unauthenticated remote attacker to perform unauthorized creation, deletion, or modification of critical data accessible through the Oracle WebLogic Server Proxy Plug-in. The full CVSS assessment indicates potential high impacts across confidentiality, integrity, and availability, meaning an attacker could not only tamper with data but potentially access sensitive information and disrupt service availability. Given the proxy plug-in's role as a gateway between web servers and WebLogic application backends, exploitation could affect downstream application data and potentially facilitate lateral movement into the WebLogic environment (Oracle CPU Jul 2026).

Exploitability

There is currently no evidence of public proof-of-concept exploit code or active in-the-wild exploitation for CVE-2026-60364. The EPSS score is approximately 0.358%, indicating a low but non-negligible probability of exploitation in the near term. The vulnerability is rated as automatable by NIST SSVC analysis, meaning exploitation could be scripted at scale. It does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time. Detection plugins have been released by Tenable (Nessus) and Qualys, enabling vulnerability scanning (Oracle CPU Jul 2026).

Mitigation and workarounds

Oracle has addressed this vulnerability as part of the July 2026 Critical Patch Update (CPU). Administrators should apply the relevant patches for Oracle WebLogic Server Proxy Plug-in versions 12.2.1.4.0 and 14.1.2.0.0, and for Oracle HTTP Server versions 12.2.1.4.0 and 14.1.2.0.0, as documented in the Oracle Fusion Middleware patch availability documentation. As a temporary workaround, Oracle recommends blocking network access via HTTP to the proxy plug-in from untrusted sources using network access controls or firewalls. Oracle strongly advises against relying on network-level mitigations as a long-term solution and urges prompt patch application (Oracle CPU Jul 2026).

Additional resources


SourceThis report was generated using AI

Related Weblogic Server Proxy Plug-in for Apache HTTP Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-60365CRITICAL10
  • Weblogic Server Proxy Plug-in for Apache HTTP Server logoWeblogic Server Proxy Plug-in for Apache HTTP Server
  • cpe:2.3:a:oracle:weblogic_server_proxy_plug-in
NoNoJul 21, 2026
CVE-2026-21962CRITICAL10
  • Weblogic Server Proxy Plug-in for Apache HTTP Server logoWeblogic Server Proxy Plug-in for Apache HTTP Server
  • cpe:2.3:a:oracle:weblogic_server_proxy_plug-in
YesNoJan 20, 2026
CVE-2026-60364CRITICAL9.8
  • Weblogic Server Proxy Plug-in for Apache HTTP Server logoWeblogic Server Proxy Plug-in for Apache HTTP Server
  • cpe:2.3:a:oracle:weblogic_server_proxy_plug-in
NoYesJul 21, 2026
CVE-2020-35169CRITICAL9.8
  • Oracle Database Server logoOracle Database Server
  • cpe:2.3:a:oracle:database
NoYesJul 11, 2022
CVE-2020-35168CRITICAL9.8
  • Oracle Database Server logoOracle Database Server
  • cpe:2.3:a:oracle:database
NoYesJul 11, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management