Oracle WLS Proxy Plugin Unauth Remote DoS 12.2.1.4/14.1.2
CVE-2026-60364 Published on July 21, 2026
Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for Third-Party Web Servers). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Weblogic Server Proxy Plug-in. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Weblogic Server Proxy Plug-in accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
Vulnerability Analysis
CVE-2026-60364 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.
Weakness Type
What is an Authorization Vulnerability?
The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVE-2026-60364 has been classified to as an Authorization vulnerability or weakness.
Products Associated with CVE-2026-60364
Want to know whenever a new CVE is published for Oracle products? stack.watch will email you.
Affected Versions
Oracle Corporation Oracle HTTP Server:- Version 12.2.1.4.0 is affected.
- Version 14.1.2.0.0 is affected.
- Version 12.2.1.4.0 is affected.
- Version 14.1.2.0.0 is affected.