DIRAS TAKE
Urgent: treat this as a high-priority mitigation because the flaw allows unauthenticated HTTP access to full server compromise and no fixes are listed for affected releases. Immediately restrict network exposure and follow Oracle’s guidance until a patch is available.
What is CVE-2026-83021?
An unauthenticated attacker with network access over HTTP can fully compromise Oracle WebLogic Server, leading to takeover of the server and potential impact to additional products. CVE-2026-83021 affects Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0; the flaw requires only network access via HTTP and no valid credentials. The vulnerability has a CVSS 3.1 base score of 10.0 indicating complete confidentiality, integrity and availability loss on vulnerable instances. The weakness is classified as CWE-287 (Improper Authentication).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Which versions of Oracle Oracle WebLogic Server are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 12.x | 12.2.1.4.0 | |
| 14.x | 14.1.1.0.0 | |
| 14.x | 14.1.2.0.0 |
Is CVE-2026-83021 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-83021
- Restrict HTTP access to WebLogic instances by blocking or limiting inbound connections at the network perimeter and using allowlists for management interfaces
- Isolate affected servers with network segmentation and remove internet exposure for WebLogic administration and application ports
- Enable and increase logging and monitoring for unusual HTTP requests and post-authentication activity on WebLogic hosts
- Follow Oracle vendor guidance for this issue and prepare to apply vendor-supplied patches or updates as soon as they are released
Frequently asked questions
Is CVE-2026-83021 being actively exploited?
There are no public reports of exploitation of CVE-2026-83021 as of 2026-09-30.
Which Oracle WebLogic Server versions are affected by CVE-2026-83021?
Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0 are listed as affected.
Is there a patch for CVE-2026-83021?
No fixed versions are listed for the affected releases; a vendor patch is not available as of 2026-09-30.
Does CVE-2026-83021 require authentication?
No, the vulnerability can be exploited without authentication; an attacker only needs network access via HTTP to target Oracle WebLogic Server.
References
- nvd.nist.gov/vuln/detail/CVE-2026-83021
- cve.org/CVERecord?id=CVE-2026-83021
- oracle.com/security-alerts/cspusep2026.html
- All Oracle CVEs on CVE Radar
- CVEs published in September 2026