CVE-2026-35303: WebLogic Server Console Vulnerability – Patch & Detection Guide
A vulnerability exists in Oracle WebLogic Server's Console component that allows authenticated users with low-level privileges to gain complete control of the server through the web interface. An attacker who already has basic access to your network can exploit this flaw without user interaction to read sensitive data, modify system configurations, and disrupt service availability. The vulnerability affects WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 8.8 HIGH · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Weaknesses (CWE)
- CWE-306
- Affected products
- 2 configuration(s)
- Published / Modified
- 2026-06-17 / 2026-06-19
NVD description (verbatim)
Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebLogic Server. Successful attacks of this vulnerability can result in takeover of WebLogic Server. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-35303 is an authentication and authorization weakness (CWE-306) in the WebLogic Server Console component. The vulnerability permits a low-privileged network user to perform unauthorized actions that compromise confidentiality, integrity, and availability. The attack vector is network-based via HTTP, requires low attack complexity, and necessitates valid user credentials but no user interaction. The CVSS 3.1 score of 8.8 reflects high impact across all security properties: attackers can exfiltrate data, modify running configurations, and terminate processes or services.
Business impact
A successful exploitation of this vulnerability could result in complete operational compromise of WebLogic Server instances. Adversaries could access confidential business data, alter application behavior, deploy malicious code, or render services unavailable. For organizations relying on WebLogic for critical middleware functions—such as application serving, message brokering, or identity management—this represents a path to lateral movement within the infrastructure and potential business disruption. The requirement for authenticated access slightly reduces immediate exposure but remains critical for any user account that may be compromised or misused.
Affected systems
Oracle WebLogic Server versions 12.2.1.4.0 (12c Release 2) and 14.1.1.0.0 (14c Release 1) are confirmed vulnerable. Organizations should verify all deployed instances against these specific versions. Patch status and workarounds should be confirmed through the Oracle Security Advisory for CVE-2026-35303.
Exploitability
The vulnerability is easily exploitable by an attacker with valid network credentials and basic system access. No special tools, zero-day knowledge, or advanced techniques are required once authentication is obtained. The low attack complexity and absence of user interaction requirements mean that exploitation can be automated and scaled. However, the requirement for low-level authenticated access provides a single control point: securing user credentials and limiting network access to the WebLogic Console reduces immediate risk.
Remediation
Organizations should prioritize patching WebLogic Server instances to versions that address CVE-2026-35303. Consult Oracle's official security advisory for approved patch levels and release dates. Interim mitigations include: restricting network access to the WebLogic Console to trusted administrative networks only, implementing strong authentication controls, monitoring for suspicious console activity, and reviewing user privilege assignments to limit the blast radius if a low-privileged account is compromised.
Patch guidance
Verify the latest Oracle WebLogic Server security advisory to identify the available patched versions for your deployment. Apply patches first to non-production environments to validate compatibility with your applications and custom configurations. Schedule patching during maintenance windows to minimize disruption. For versions 12.2.1.4.0 and 14.1.1.0.0, confirm that your target patch version is documented as resolving CVE-2026-35303 before deployment.
Detection guidance
Monitor WebLogic Server logs for unusual Console access patterns, particularly from low-privileged accounts performing administrative actions. Watch for failed or suspicious authentication attempts, rapid privilege escalation attempts, or console API calls that deviate from normal baselines. Network intrusion detection systems should be tuned to flag unauthorized HTTP requests to the Console port from unexpected sources. Endpoint detection tools can flag process execution or file modification anomalies on WebLogic Server hosts that may indicate post-exploitation activity.
Why prioritize this
This vulnerability merits urgent patching due to its high CVSS score (8.8), complete impact on confidentiality, integrity, and availability, and the ease of exploitation once network credentials are obtained. Although it requires authenticated access, the low barrier to entry and high business impact make it a top target for adversaries seeking to move laterally within a compromised network or for insiders abusing legitimate credentials. Organizations should treat this as critical in their patch management queue.
Risk score, explained
The CVSS 3.1 score of 8.8 (HIGH severity) reflects a network-accessible vulnerability with low attack complexity that requires only low-level privileges and produces complete system compromise. The score accounts for high impact on confidentiality (data exposure), integrity (unauthorized modification), and availability (service disruption). The absence of required user interaction after initial authentication and the lack of scope escalation limit the score from critical, but the overall risk remains substantial given the ease of exploitation and complete control granted to an attacker.
Frequently asked questions
Do we need to patch immediately if our WebLogic Server is not internet-facing?
Yes. The vulnerability requires network access but not necessarily public-internet exposure. If your WebLogic Server is accessible to internal users, contractors, or systems on corporate networks, or if a low-privileged account could be compromised through phishing or malware, the risk remains high. Patch on an expedited timeline regardless of network topology.
Can we use a firewall or WAF to protect against this vulnerability?
Network segmentation and access controls can reduce exposure by limiting who can reach the Console, but they do not eliminate the vulnerability itself. A compromised internal account or an authorized user abusing their credentials will still be able to exploit the flaw. These controls are valuable interim steps but must be paired with patching.
Is there a workaround if we cannot patch immediately?
Interim mitigation involves disabling or restricting Console access to only essential administrative accounts and IP ranges, implementing multi-factor authentication for Console access if available, and monitoring logs for suspicious activity. However, these are temporary measures. Prioritize patching within your change management process rather than relying solely on compensating controls.
What should we do if we suspect exploitation of this vulnerability?
Immediately isolate the affected WebLogic Server, preserve logs and memory for forensic analysis, review recent Console activity and authentication logs, and assess what data or configurations may have been accessed or modified. Engage incident response and threat intelligence teams to determine the scope of compromise and whether lateral movement has occurred within your environment.
This analysis is provided for informational purposes and reflects the vulnerability data available as of the publication date. Security teams should verify all patch versions, timelines, and applicability with Oracle's official security advisories and their own vendor documentation. No exploit code or weaponized proof-of-concepts are provided. Organizations should conduct their own risk assessments and testing before applying patches to production systems. SEC.co makes no warranty regarding the accuracy or completeness of remediation guidance and recommends engagement with Oracle Support for environment-specific questions. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-35265HIGHOracle Identity Manager Authentication Bypass – Critical Patch Required
- CVE-2026-35267HIGHOracle Identity Manager REST WebServices Authentication Bypass (CVSS 8.8)
- CVE-2026-35274HIGHOracle PeopleSoft PT PeopleTools Authentication Bypass
- CVE-2026-35276HIGHOracle PeopleSoft Authentication Bypass Vulnerability (8.1 CVSS)
- CVE-2026-35279HIGHPeopleSoft PT PeopleTools Authentication Bypass – Critical Patch Guidance
- CVE-2026-35289HIGHOracle PeopleSoft PT PeopleTools Authentication Bypass (CVSS 8.1)
- CVE-2026-35295HIGHOracle WebCenter Sites Authentication Bypass – High Risk Patch Alert
- CVE-2026-35299HIGHOracle WebLogic Server Console Authentication Bypass (CVSS 8.8)