CVE-2026-35292: Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console)
Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise WebLogic Server. While the vulnerability is in WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of WebLogic Server. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
Metrics
- CVSS v3.1
- 10.0
- Severity
- CRITICAL
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
This is a complete server takeover vulnerability in the Oracle WebLogic Server Console component, affecting versions 14.1.2.0.0 and 15.1.1.0.0. An unauthenticated attacker reachable over HTTP can exploit this without any credentials or victim interaction, and the CVSS scope change means the impact extends beyond the WebLogic process itself to other products sharing the environment. Successful exploitation gives the attacker full control over the server, including the ability to read all data, modify any persisted state, and crash or destabilize the service. No fix versions have been published yet; HarborGuard tracks the advisory and will make a patched-image rebuild available the moment Oracle ships a patch.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in all connected registries and CI/CD pipelines, including custom-built WebLogic images. Any image shipping WebLogic Server 14.1.2.0.0 or 15.1.1.0.0 is flagged immediately upon the next pipeline scan or registry push.
AvailableHarborGuard surfaces this CVE with its full CVSS 3.1 score of 10.0 (Critical), applies per-environment compliance policy weighting, and routes the finding to the appropriate team inbox within each customer organization. The scope-change flag (S:C) is preserved in the finding detail so triagers understand the blast extends past the directly affected container.
AvailableBecause no fix version has been published, HarborGuard re-checks the Oracle advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment an upstream fix is released. For customers with auto-remediation enabled, the rebuild, regression-test run, and PR against affected workloads will be triggered without manual intervention as soon as a patch version is confirmed.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must reach the WebLogic Console over the network via HTTP; no physical or local access is required.
- AuthenticationNot required
No credentials of any kind are needed; the vulnerability is exploitable by a completely unauthenticated attacker.
- Victim interactionNot required
No user action is required; the attacker can exploit the vulnerability directly without involving any human target.
- Attack complexityDetail
Attack complexity is Low, meaning the exploit is reliable and does not depend on race conditions, memory layout, or any other environmental factors.
Blast Radius
- The attacker gains full read access to all data processed by the WebLogic Server, including session tokens, credentials, and application data.
- The attacker can modify or delete any persisted data managed by the server, including configuration, deployed applications, and database-backed records.
- The attacker can crash or permanently destabilize the WebLogic service, causing a full denial of service for dependent applications.
- Because the CVSS scope change applies, adjacent products and services co-located in the same environment can also be compromised, not just the WebLogic process itself.
How HarborGuard Handles This
Available on HarborGuard: because no upstream patch exists yet, HarborGuard continuously re-checks the Oracle advisory on every ingest cycle and will trigger a patched-image rebuild the moment a fix version is published. For customers with auto-remediation enabled, that rebuild will be followed immediately by a regression-test run and a PR opened against all affected workloads. In the meantime, recommended compensating controls include isolating WebLogic Console ports behind a network policy that denies inbound HTTP access from untrusted sources, applying egress filtering to limit lateral movement if a container is compromised, and disabling or gating the Console component via feature flag if it is not required in production. HarborGuard will surface any Oracle-issued advisory update or interim patch as a new finding event so affected environments are never silently out of date.
- Oracle Corporation / WebLogic Server14.1.2.0.0 · 15.1.1.0.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H