HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-35298Published Modified CNA oracle

CVE-2026-35298: Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core)

Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise WebLogic Server. While the vulnerability is in WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of WebLogic Server. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).

Metrics

CVSS v3.1
9.1
Severity
CRITICAL
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A remote code execution vulnerability exists in the Core component of Oracle WebLogic Server, affecting versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. An attacker with administrative credentials can reach the server over HTTP and exploit this flaw without any victim interaction, gaining full control of the WebLogic instance with effects that spill over into adjacent systems (a CVSS scope change). Successful exploitation gives the attacker complete read, write, and availability control over the server and potentially connected products. HarborGuard is tracking this advisory for patch availability and will make a patched-image rebuild available the moment Oracle publishes a fix.

HarborGuard Coverage

Detection

Detection of CVE-2026-35298 is available across every HarborGuard environment: the CVE is ingested from upstream Oracle and NVD feeds within minutes of publication and matched against all customer images in connected registries and CI/CD pipelines, including internally built images that bundle WebLogic. Custom base images derived from affected WebLogic versions are covered by the same matching logic.

Available
Triage

Triage is available with a CVSS 3.1 score of 9.1 (Critical), surfaced alongside per-environment compliance policy weighting so that teams running affected WebLogic versions see this routed to the appropriate security inbox at the correct priority. Policy rules defined within each customer org determine which teams and ticket queues receive the alert.

Available
Patch

Because no fix version has been published by Oracle, HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment an upstream fix is released. For customers with auto-remediation enabled, the rebuild, regression-test run, and PR against affected workloads will be initiated without manual intervention once a fix version is confirmed.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the WebLogic HTTP interface over the network; there is no local-only attack path.

  • AuthenticationRequired

    A high-privileged (administrative) account is required; low-privilege or anonymous access is not sufficient to trigger this vulnerability.

  • Victim interactionNot required

    No user action is needed; the attacker can complete the exploit entirely on their own without any victim participation.

  • Attack complexityDetail

    Attack complexity is Low, meaning the exploit is reliable and does not depend on race conditions, special memory layout, or other environmental factors outside the attacker's control.

Blast Radius

  • The attacker achieves full takeover of the WebLogic Server instance, reading all data the server can access including credentials, application data, and runtime secrets.
  • The attacker can write to or modify any data the server manages, including deployed applications, configuration files, and persisted database records reachable via the server.
  • The attacker can crash or render the WebLogic Server permanently unavailable, disrupting all dependent services and workloads.
  • Because the CVSS scope changes, the impact extends beyond WebLogic itself: adjacent systems that trust or share resources with the compromised server are also exposed to the same level of confidentiality, integrity, and availability loss.

How HarborGuard Handles This

Available on HarborGuard: because Oracle has not yet published a fix for CVE-2026-35298, HarborGuard monitors the advisory on every feed ingest cycle and will surface a patched-image rebuild the moment an upstream fix version is confirmed. In the interim, customers can apply compensating controls through HarborGuard network policy enforcement, including isolating WebLogic containers behind strict ingress rules that limit HTTP access to only known administrative source IPs and blocking unnecessary egress paths from the WebLogic container to adjacent services. Where compliance policy permits, any future patched rebuild will automatically trigger a regression-test run and a PR opened against affected workloads for environments with auto-remediation enabled. Teams without auto-remediation will receive an actionable alert with the fix version and rebuild details as soon as the upstream patch is available.

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / WebLogic Server
    12.2.1.4.0 · 14.1.1.0.0 · 14.1.2.0.0 · 15.1.1.0.0
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
References