CVE-2026-60699
Oracle WebLogic Server vulnerability analysis and mitigation

Overview

CVE-2026-60699 is an unauthenticated information disclosure vulnerability in the Core component of Oracle WebLogic Server, part of Oracle Fusion Middleware. It affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The vulnerability is easily exploitable by unauthenticated attackers with network access via the T3 or IIOP protocols, and successful exploitation can result in unauthorized access to critical data managed by the server. It carries a CVSS v3.1 base score of 8.6 (High), with a scope change indicating potential impact on additional products beyond WebLogic itself (Oracle Advisory, Feedly).

Technical details

The vulnerability resides in the Core component of Oracle WebLogic Server and is exploitable via the T3 and IIOP protocols, which are used for Java EE remote object communication and are commonly exposed on WebLogic's default listen ports. No authentication or user interaction is required, and attack complexity is low, making this straightforward to exploit remotely. The vulnerability is classified as an authentication bypass (CWE not explicitly assigned in available data), allowing attackers to read all data accessible to the WebLogic Server without credentials. The scope change in the CVSS vector indicates that exploitation can affect resources beyond the vulnerable WebLogic instance itself, such as connected backend systems or databases (Oracle Advisory, Feedly).

Impact

Successful exploitation results in complete unauthorized read access to all critical data managed by the Oracle WebLogic Server instance, including application data, configuration secrets, and potentially credentials stored or accessible by the server. The scope change means that connected products and downstream systems may also be impacted, increasing the risk of lateral movement within enterprise environments. Integrity and availability are not directly impacted by this vulnerability; the primary risk is high-severity confidentiality loss (Oracle Advisory, Feedly).

Exploitability

As of the time of disclosure (August 18, 2026), there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation. The EPSS score is 0.0, reflecting the early stage of public awareness. The vulnerability has been detected by Qualys (detection ID 87617) and is listed in Oracle's August 2026 Critical Security Patch Update. It has not been added to the CISA Known Exploited Vulnerabilities catalog at this time (Oracle Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Oracle WebLogic Server instances running versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, or 15.1.1.0.0 using tools such as Shodan or Censys, targeting default T3 (port 7001) or IIOP (port 2809) listener ports.
  2. Protocol access: Establish a network connection to the target WebLogic Server via the T3 or IIOP protocol without providing any credentials, leveraging the unauthenticated nature of the vulnerability.
  3. Data exfiltration: Send crafted T3 or IIOP protocol requests to the Core component to trigger the vulnerability and retrieve sensitive data — such as application configuration, credentials, or business data — accessible to the WebLogic Server.
  4. Lateral movement: Use any extracted credentials or configuration data to pivot to connected backend systems, databases, or other products within the enterprise environment that WebLogic has access to (Oracle Advisory, Feedly).

Indicators of compromise

  • Network: Unexpected or anomalous unauthenticated connections to WebLogic T3 (default port 7001) or IIOP (default port 2809) listener ports from external or untrusted IP addresses; unusual volume of T3/IIOP traffic from a single source.
  • Logs: WebLogic server logs (server.log) showing unauthenticated T3 or IIOP requests accessing Core component resources; access log entries with no associated authenticated session for sensitive data endpoints.
  • Process: Unusual outbound network connections from the WebLogic JVM process to external hosts following inbound T3/IIOP activity, potentially indicating data exfiltration.

Mitigation and workarounds

Oracle has addressed this vulnerability as part of the August 2026 Critical Security Patch Update (CSPU); administrators should apply the relevant patches for their affected versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0) immediately. As a temporary workaround prior to patching, restrict network access to the T3 and IIOP protocols to trusted IP ranges only using firewall rules or WebLogic's built-in connection filter. Implement network segmentation to limit exposure of WebLogic Server instances to the internet or untrusted networks, and monitor for unauthorized access attempts via these protocols (Oracle Advisory, Feedly).

Additional resources

  • Oracle Advisory — Oracle August 2026 Critical Security Patch Update Advisory
  • ENISA EUVD — ENISA European Vulnerability Database Entry

SourceThis report was generated using AI

Related Oracle WebLogic Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-60702CRITICAL9.9
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesAug 18, 2026
CVE-2026-60977CRITICAL9.8
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesAug 18, 2026
CVE-2026-60698CRITICAL9.8
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesAug 18, 2026
CVE-2026-60696CRITICAL9.8
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesAug 18, 2026
CVE-2026-60699HIGH8.6
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management