CVE-2026-35258: Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console)
Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise WebLogic Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all WebLogic Server accessible data as well as unauthorized access to critical data or complete access to all WebLogic Server accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).
Metrics
- CVSS v3.1
- 8.7
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
A stored or reflected cross-site scripting class vulnerability (scope-changing, high-impact) affects the Console component of Oracle WebLogic Server versions 14.1.2.0.0 and 15.1.1.0.0. An authenticated attacker with any low-privilege account can reach the Console over HTTPS and trigger the vulnerability by inducing another user to interact with a crafted request or link. Successful exploitation gives the attacker full read and write access to critical WebLogic Server data, with impact that can spill beyond the WebLogic instance itself into adjacent components. HarborGuard is tracking this advisory and will make a patched-image rebuild available the moment Oracle publishes a fix version.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from Oracle and NVD feeds within minutes of publication and matched against all customer images, including custom-built images derived from WebLogic base layers. Any image containing WebLogic Server 14.1.2.0.0 or 15.1.1.0.0 is flagged automatically at the next pipeline scan.
AvailableHarborGuard scores this finding at CVSS 8.7 (HIGH) and applies per-environment compliance policy weighting to determine priority and routing. Findings are directed to the appropriate team inbox within each customer organization based on configured ownership rules for affected image namespaces.
AvailableNo fix version has been published by Oracle for this CVE. HarborGuard re-checks the upstream advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment Oracle ships a corrective release. For customers who opt into auto-remediation, the rebuild, regression test run, and pull request against affected workloads will be triggered without manual intervention once the fix becomes available.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must reach the WebLogic Console over the network via HTTPS; the service must be exposed to the attacker's network segment.
- AuthenticationRequired
A low-privilege account is sufficient; no administrative or elevated credentials are needed to initiate the attack.
- Victim interactionRequired
A separate authenticated user (other than the attacker) must interact with a crafted link or request, making social engineering a necessary step in the attack chain.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, memory layout, or other variable environmental factors.
Blast Radius
- Reads all data accessible to the WebLogic Server, including stored credentials, configuration secrets, and application data.
- Modifies or deletes any data accessible to the WebLogic Server, including persisted application records and server configuration.
- Because the CVSS scope is changed, impact can extend beyond the WebLogic instance itself to other components or products sharing the same host or trust boundary.
How HarborGuard Handles This
Available on HarborGuard: because Oracle has not yet published a fix for this CVE, the platform monitors the upstream advisory on every ingest cycle and will generate a patched-image rebuild automatically once a corrective release appears. In the meantime, compensating controls worth applying include restricting network access to the WebLogic Console to known trusted IP ranges via network policy, enforcing egress filtering to limit lateral movement if the Console is compromised, and disabling Console access entirely in environments where it is not operationally required. Customers with auto-remediation enabled will receive the rebuild, a regression test run, and a PR opened against affected workloads as soon as a fix version is published, with no manual steps required. Where compliance policy requires human approval before merge, the PR is created and held for review.
- Oracle Corporation / WebLogic Server14.1.2.0.0 · 15.1.1.0.0
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N