Summary
CVE-2026-60698 is a critical vulnerability in the Core component of Oracle WebLogic Server that allows an unauthenticated attacker with network access via IIOP to compromise the server, resulting in complete takeover of confidentiality, integrity, and availability. Oracle rates the flaw 9.8 (Critical) under CVSS v3.1, and it was disclosed in Oracle’s August 2026 Critical Patch Update.
Technical details
- Root cause: A flaw in the WebLogic Server Core component reachable through the IIOP (Internet Inter-ORB Protocol) network protocol.
- Trigger conditions: No authentication or user interaction is required; the attacker only needs network access to a WebLogic listener that accepts IIOP.
- Attack vector: Network (AV:N), low attack complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N).
- Impact: Successful exploitation can lead to complete compromise of the WebLogic Server, affecting confidentiality, integrity, and availability (C:H/I:H/A:H).
Affected software
- Oracle WebLogic Server 12.2.1.4.0
- Oracle WebLogic Server 14.1.1.0.0
- Oracle WebLogic Server 14.1.2.0.0
- Oracle WebLogic Server 15.1.1.0.0
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the patches provided in Oracle’s August 2026 Critical Patch Update for the affected WebLogic Server versions listed above.
- If immediate patching is not possible: Restrict or disable network access to the IIOP protocol on WebLogic Server listen ports, particularly from untrusted networks, and limit exposure of WebLogic administration and T3/IIOP interfaces to the internet until patches can be applied.

