Summary
CVE-2026-60699 is a vulnerability in the Core component of Oracle WebLogic Server that allows an unauthenticated, network-based attacker to gain unauthorized access to critical data by sending crafted traffic over the T3 or IIOP protocols. Oracle rates it easily exploitable and disclosed it in the August 2026 Critical Patch Update. The flaw carries a CVSS v3.1 base score of 8.6 (High), with a scope change indicating impact beyond the WebLogic Server component itself.
Technical details
- Root cause: A weakness in Oracle WebLogic Server’s Core component reachable through the T3 and IIOP remote protocols used for RMI/EJB communication.
- Trigger conditions: No authentication or user interaction is required; the attacker only needs network access to the WebLogic listener ports that expose T3/IIOP.
- Attack vector: Network (AV:N), low attack complexity (AC:L), no privileges required (PR:N).
- Impact: High confidentiality impact resulting in unauthorized access to critical data; no direct impact to integrity or availability. The CVSS scope change (S:C) reflects that the vulnerability can affect resources beyond the vulnerable component.
Affected software
- Oracle WebLogic Server 12.2.1.4.0
- Oracle WebLogic Server 14.1.1.0.0
- Oracle WebLogic Server 14.1.2.0.0
- Oracle WebLogic Server 15.1.1.0.0
Severity
- CVSS v3.1 Base Score: 8.6 (High)
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Apply the Oracle WebLogic Server patches issued in the August 2026 Critical Patch Update for the affected 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 releases.
- If patching cannot be performed immediately: Restrict or disable network access to the T3 and IIOP protocols at the firewall/network layer, limiting exposure to trusted internal hosts only, since the vulnerability is remotely exploitable over these channels without authentication.

