
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-60699 is an unauthenticated information disclosure vulnerability in the Core component of Oracle WebLogic Server, part of Oracle Fusion Middleware. It affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The vulnerability is easily exploitable by unauthenticated attackers with network access via the T3 or IIOP protocols, and successful exploitation can result in unauthorized access to critical data managed by the server. It carries a CVSS v3.1 base score of 8.6 (High), with a scope change indicating potential impact on additional products beyond WebLogic itself (Oracle Advisory, Feedly).
The vulnerability resides in the Core component of Oracle WebLogic Server and is exploitable via the T3 and IIOP protocols, which are used for Java EE remote object communication and are commonly exposed on WebLogic's default listen ports. No authentication or user interaction is required, and attack complexity is low, making this straightforward to exploit remotely. The vulnerability is classified as an authentication bypass (CWE not explicitly assigned in available data), allowing attackers to read all data accessible to the WebLogic Server without credentials. The scope change in the CVSS vector indicates that exploitation can affect resources beyond the vulnerable WebLogic instance itself, such as connected backend systems or databases (Oracle Advisory, Feedly).
Successful exploitation results in complete unauthorized read access to all critical data managed by the Oracle WebLogic Server instance, including application data, configuration secrets, and potentially credentials stored or accessible by the server. The scope change means that connected products and downstream systems may also be impacted, increasing the risk of lateral movement within enterprise environments. Integrity and availability are not directly impacted by this vulnerability; the primary risk is high-severity confidentiality loss (Oracle Advisory, Feedly).
As of the time of disclosure (August 18, 2026), there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation. The EPSS score is 0.0, reflecting the early stage of public awareness. The vulnerability has been detected by Qualys (detection ID 87617) and is listed in Oracle's August 2026 Critical Security Patch Update. It has not been added to the CISA Known Exploited Vulnerabilities catalog at this time (Oracle Advisory, Feedly).
server.log) showing unauthenticated T3 or IIOP requests accessing Core component resources; access log entries with no associated authenticated session for sensitive data endpoints.Oracle has addressed this vulnerability as part of the August 2026 Critical Security Patch Update (CSPU); administrators should apply the relevant patches for their affected versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0) immediately. As a temporary workaround prior to patching, restrict network access to the T3 and IIOP protocols to trusted IP ranges only using firewall rules or WebLogic's built-in connection filter. Implement network segmentation to limit exposure of WebLogic Server instances to the internet or untrusted networks, and monitor for unauthorized access attempts via these protocols (Oracle Advisory, Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."