CVE-2026-35292 -- CVSS 10.0 Vulnerability Briefing
CVE-2026-35292 | CVSS 10.0 (Critical) | Exploit: No known exploit
What Is It
CVE-2026-35292 is a critical unauthenticated remote code execution vulnerability in the Console component of Oracle WebLogic Server, affecting versions 14.1.2.0.0 and 15.1.1.0.0.
Technical Detail
The flaw resides in the WebLogic Server Console and is described by Oracle as "easily exploitable," allowing an unauthenticated attacker with network access via HTTP to compromise the server without requiring any user interaction or credentials. The vulnerability carries a CVSS score of 10.0, indicating complete loss of confidentiality, integrity, and availability upon successful exploitation. If triggered, an attacker could achieve full remote code execution on the underlying host, potentially gaining operating system-level control of the affected server.
Exploitation Status
No known exploit has been publicly documented or observed as of June 24, 2026. This vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog. While no proof-of-concept or operational exploit has been confirmed, the unauthenticated, network-accessible attack vector and maximum CVSS score make this a high-priority target for future exploitation attempts.
Who Is Targeting This
No specific threat actor attribution at this time. Neither confirmed nor reported threat actor activity has been associated with CVE-2026-35292 as of this writing. However, Oracle WebLogic Server has historically been a high-value target for financially motivated and state-sponsored actors, and the profile of this vulnerability warrants close monitoring for emerging attribution.
What To Do
Apply Oracle's patch for WebLogic Server versions 14.1.2.0.0 and 15.1.1.0.0 immediately, prioritizing internet-facing or externally accessible deployments. If patching cannot be completed immediately, restrict network access to the WebLogic Administration Console to trusted management networks only, and block HTTP access to the console from untrusted sources at the perimeter. Monitor WebLogic server logs for anomalous HTTP requests targeting console endpoints, unexpected process spawning from the WebLogic process, and unusual outbound network connections from the server host. Given the maximum severity rating and ease of exploitation, this should be treated as an emergency patch cycle item regardless of current exploitation status.