CVE-2026-35298: Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core)
Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise WebLogic Server. While the vulnerability is in WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of WebLogic Server. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
Metrics
- CVSS v3.1
- 9.1
- Severity
- CRITICAL
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
A remote code execution vulnerability exists in the Core component of Oracle WebLogic Server, affecting versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. An attacker with administrative credentials can reach the server over HTTP and exploit this flaw without any victim interaction, gaining full control of the WebLogic instance with effects that spill over into adjacent systems (a CVSS scope change). Successful exploitation gives the attacker complete read, write, and availability control over the server and potentially connected products. HarborGuard is tracking this advisory for patch availability and will make a patched-image rebuild available the moment Oracle publishes a fix.
HarborGuard Coverage
Detection of CVE-2026-35298 is available across every HarborGuard environment: the CVE is ingested from upstream Oracle and NVD feeds within minutes of publication and matched against all customer images in connected registries and CI/CD pipelines, including internally built images that bundle WebLogic. Custom base images derived from affected WebLogic versions are covered by the same matching logic.
AvailableTriage is available with a CVSS 3.1 score of 9.1 (Critical), surfaced alongside per-environment compliance policy weighting so that teams running affected WebLogic versions see this routed to the appropriate security inbox at the correct priority. Policy rules defined within each customer org determine which teams and ticket queues receive the alert.
AvailableBecause no fix version has been published by Oracle, HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment an upstream fix is released. For customers with auto-remediation enabled, the rebuild, regression-test run, and PR against affected workloads will be initiated without manual intervention once a fix version is confirmed.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must reach the WebLogic HTTP interface over the network; there is no local-only attack path.
- AuthenticationRequired
A high-privileged (administrative) account is required; low-privilege or anonymous access is not sufficient to trigger this vulnerability.
- Victim interactionNot required
No user action is needed; the attacker can complete the exploit entirely on their own without any victim participation.
- Attack complexityDetail
Attack complexity is Low, meaning the exploit is reliable and does not depend on race conditions, special memory layout, or other environmental factors outside the attacker's control.
Blast Radius
- The attacker achieves full takeover of the WebLogic Server instance, reading all data the server can access including credentials, application data, and runtime secrets.
- The attacker can write to or modify any data the server manages, including deployed applications, configuration files, and persisted database records reachable via the server.
- The attacker can crash or render the WebLogic Server permanently unavailable, disrupting all dependent services and workloads.
- Because the CVSS scope changes, the impact extends beyond WebLogic itself: adjacent systems that trust or share resources with the compromised server are also exposed to the same level of confidentiality, integrity, and availability loss.
How HarborGuard Handles This
Available on HarborGuard: because Oracle has not yet published a fix for CVE-2026-35298, HarborGuard monitors the advisory on every feed ingest cycle and will surface a patched-image rebuild the moment an upstream fix version is confirmed. In the interim, customers can apply compensating controls through HarborGuard network policy enforcement, including isolating WebLogic containers behind strict ingress rules that limit HTTP access to only known administrative source IPs and blocking unnecessary egress paths from the WebLogic container to adjacent services. Where compliance policy permits, any future patched rebuild will automatically trigger a regression-test run and a PR opened against affected workloads for environments with auto-remediation enabled. Teams without auto-remediation will receive an actionable alert with the fix version and rebuild details as soon as the upstream patch is available.
- Oracle Corporation / WebLogic Server12.2.1.4.0 · 14.1.1.0.0 · 14.1.2.0.0 · 15.1.1.0.0
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H