ZeroHour

CVE-2026-83038

large

Low-Privilege Authenticated RCE in Oracle WebLogic Server TopLink Integration

CVSS 3.1
9.9 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-83038 is a critical (CVSS 9.9) vulnerability in the TopLink Integration component of Oracle WebLogic Server, part of Oracle Fusion Middleware. A remote attacker who already holds low-privileged credentials for the server and has HTTP network access can exploit the flaw easily, and a successful attack results in a complete takeover of Oracle WebLogic Server. The CVSS vector includes a scope change (S:C), meaning compromise of WebLogic can significantly impact additional products beyond the vulnerable component itself, with high impact on confidentiality, integrity, and availability. Affected deployments are those running WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, or 15.1.1.0.0. As of this analysis, the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, so there is no confirmed in-the-wild exploitation.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83038 to all WebLogic Server installations running 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, or 15.1.1.0.0. Because exploitation requires only low-privileged HTTP access, restrict management and application HTTP endpoints to trusted networks/VPNs, enforce strong authentication and least-privilege on all WebLogic accounts, and audit low-privilege accounts for abuse. Review servers for signs of post-exploitation such as unexpected deployments, scheduled jobs, or new OS-level users, since successful attacks lead to full server takeover with scope change to adjacent products.

Affected
Oracle WebLogic Server (Oracle Fusion Middleware, component: TopLink Integration)12.2.1.4.0
Oracle WebLogic Server (Oracle Fusion Middleware, component: TopLink Integration)14.1.1.0.0
Oracle WebLogic Server (Oracle Fusion Middleware, component: TopLink Integration)14.1.2.0.0
Oracle WebLogic Server (Oracle Fusion Middleware, component: TopLink Integration)15.1.1.0.0
Estimated exposure
largeOn the order of tens of thousands of internet-exposed WebLogic servers (roughly 10,000–100,000), plus a substantial internal enterprise estate — Public internet scans (e.g., Shodan/Censys) consistently show tens of thousands of WebLogic admin/console endpoints exposed, and WebLogic is widely deployed in large enterprise and government data centers, most of which run the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: TopLink Integration). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.