Summary
CVE-2026-60415 is a vulnerability in the Core component of Oracle WebLogic Server that allows an unauthenticated attacker with network access via the T3 or IIOP protocols to compromise the server, with successful exploitation potentially resulting in complete takeover. Oracle rates this a difficult-to-exploit issue but assigns it a CVSS v3.1 base score of 8.1, reflecting high impact to confidentiality, integrity, and availability. The flaw was disclosed in Oracle’s August 2026 Critical Security Patch Update.
Technical details
- Root cause: A weakness in the WebLogic Server Core component reachable through the T3 and IIOP protocols.
- Trigger conditions: No authentication or user interaction is required, but Oracle classifies attack complexity as high, meaning exploitation depends on conditions not fully within the attacker’s control.
- Attack vector: Network-based, over T3 and/or IIOP — protocols commonly used for WebLogic’s RMI-based inter-server and client communication.
- Impact: Successful exploitation can lead to complete compromise of the WebLogic Server, affecting confidentiality, integrity, and availability.
Affected software
- Oracle WebLogic Server 12.2.1.4.0
- Oracle WebLogic Server 14.1.1.0.0
- Oracle WebLogic Server 14.1.2.0.0
- Oracle WebLogic Server 15.1.1.0.0
Severity
- CVSS v3.1 Base Score: 8.1 (High)
- Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the Oracle patches released in the August 2026 Critical Security Patch Update for the affected WebLogic Server versions listed above.
- If patching is delayed: Restrict or disable network access to the T3 and IIOP protocols at the network perimeter and internally (e.g., firewall rules blocking T3/T3S and IIOP ports), since exploitation depends on network reachability of these protocols. Limit WebLogic administrative and inter-server communication to trusted internal networks only.

