HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-35303Published Modified CNA oracle

CVE-2026-35303: Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console)

Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebLogic Server. Successful attacks of this vulnerability can result in takeover of WebLogic Server. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

An authentication-bypass-level privilege escalation vulnerability exists in the Console component of Oracle WebLogic Server (versions 12.2.1.4.0 and 14.1.1.0.0). The flaw is reachable over the network via HTTP and requires only a low-privileged account, with no victim interaction needed. Successful exploitation gives an attacker full control over the WebLogic Server instance, covering confidentiality, integrity, and availability. No fix version has been published yet; HarborGuard is tracking this advisory and will surface a patched-image rebuild the moment Oracle releases one.

HarborGuard Coverage

Detection

Detection for CVE-2026-35303 is available across every HarborGuard environment, with the CVE matched against images in customer registries and CI/CD pipelines within minutes of publication. This coverage extends to custom-built images that bundle WebLogic Server components, not only images pulled directly from Oracle's registry.

Available
Triage

HarborGuard is capable of scoring this CVE at its published CVSS 3.1 rating of 8.8 (HIGH) and weighting it against each customer organization's compliance policy to determine urgency. Findings are routed to the appropriate team inbox within each customer org based on ownership rules configured in that environment.

Available
Patch

Because no upstream fix version exists for CVE-2026-35303, HarborGuard re-checks the Oracle advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment a fix is published. For customers who opt into auto-remediation, that rebuild will trigger a regression test run and a PR opened against affected workloads without manual intervention.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the WebLogic Console over the network via HTTP; there is no local or physical access requirement.

  • AuthenticationRequired

    A low-privileged account is sufficient; the attacker does not need administrative credentials, but some valid login is required.

  • Victim interactionNot required

    No user action is needed; the attacker can exploit the flaw directly without involving any other person.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other unpredictable environmental factors.

Blast Radius

  • A successful attacker reads all data accessible to the WebLogic Server process, including application secrets, session tokens, and any credentials stored or cached by the server.
  • The attacker can write or modify persisted application data, configuration files, and deployed artifacts on the server.
  • The attacker can crash or hang the WebLogic Server process, taking down hosted applications and any services that depend on them.
  • Full server takeover is achievable, allowing the attacker to deploy arbitrary code or use the compromised instance as a foothold into adjacent internal systems.

How HarborGuard Handles This

Available on HarborGuard: because Oracle has not yet published a fix for CVE-2026-35303, the platform monitors the upstream advisory on every ingest cycle and will automatically make a patched-image rebuild available the moment a fix version is released. For customers who opt into auto-remediation, that rebuild will be followed immediately by a regression-test run and a PR opened against any affected workloads. In the interim, compensating controls are worth considering: network-policy rules that restrict access to the WebLogic Console port (typically 7001/7002) to known management IP ranges, egress filtering to limit lateral movement from a compromised instance, and disabling the Console component entirely if it is not operationally required. HarborGuard will surface a priority alert at the 8.8 HIGH score level when a fix version becomes available, ensuring affected environments are not left waiting on manual checks.

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / WebLogic Server
    12.2.1.4.0 · 14.1.1.0.0
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References