CVE-2026-60365
Oracle Weblogic Server Proxy Plug‑in version 15.1.1.0.0 has a critical flaw that lets anyone on the network use HTTP to take control of the plug‑in. The vulnerability can be exploited without authentication or user interaction. A successful attack gives the attacker full access to the data the plug‑in manages.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Oracle Weblogic Server Proxy Plug‑in for Third‑Party Web Servers, version 15.1.1.0.0, used by Oracle Fusion Middleware customers.
Real-world impact
An attacker can create, delete, or modify data and gain unrestricted access to all data exposed through the plug‑in, potentially compromising sensitive business information.
Why this severity
The CVSS score of 10 reflects that the flaw is network‑exposed, requires no authentication, and allows complete confidentiality and integrity compromise with a scope change, making it a top‑tier threat.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jul 21, 2026 · 11d agoPublishedDisclosed and added to the National Vulnerability Database.
- Aug 1, 2026 · 14h agoAdvisory updatedThe NVD record was last revised.