CVE-2026-83021
largeUnauthenticated HTTP Takeover Flaw in Oracle WebLogic Server Web Container
CVE-2026-83021 is a critical (CVSS 3.1 base score 10.0) vulnerability in the Web Container component of Oracle WebLogic Server, part of Oracle Fusion Middleware. It is triggered remotely by an unauthenticated attacker sending crafted requests over HTTP to an affected WebLogic instance, requiring no privileges or user interaction. A successful exploit results in a complete takeover of Oracle WebLogic Server, and because the CVSS scope is changed, successful attacks may also significantly impact additional products beyond WebLogic itself. The supported affected versions are 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0. As of this writing, the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, though WebLogic's history as a high-value target makes prompt patching essential.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83021 to all WebLogic Server installations running 12.2.1.4.0, 14.1.1.0.0, or 14.1.2.0.0 as soon as it is available, prioritizing any instance reachable over HTTP. Until patched, restrict network access to WebLogic HTTP/Admin listen ports (e.g., 7001/7002) to trusted sources via firewall rules, and review logs for unauthenticated anomalous HTTP requests against the Web Container. Also assess connected products and services, since successful attacks can impact systems beyond WebLogic itself.
| Oracle WebLogic Server (Oracle Fusion Middleware, component: Web Container) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.