CVE-2026-83021: unauthenticated remote takeover in Oracle Oracle WebLogic Server

An unauthenticated attacker with network access over HTTP can fully compromise Oracle WebLogic Server, leading to takeover of the server and potential impact to additional products. CVE-2026-83021 affects Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0; the flaw requires only network access via HTTP and no valid credentials. The vulnerability has a CVSS 3.1 base score of 10.0 indicating complete confidentiality, integrity and availability loss on vulnerable instances.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
10CRITICAL
EPSS
0.00508
CWE
CWE-287
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: treat this as a high-priority mitigation because the flaw allows unauthenticated HTTP access to full server compromise and no fixes are listed for affected releases. Immediately restrict network exposure and follow Oracle’s guidance until a patch is available.

What is CVE-2026-83021?

An unauthenticated attacker with network access over HTTP can fully compromise Oracle WebLogic Server, leading to takeover of the server and potential impact to additional products. CVE-2026-83021 affects Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0; the flaw requires only network access via HTTP and no valid credentials. The vulnerability has a CVSS 3.1 base score of 10.0 indicating complete confidentiality, integrity and availability loss on vulnerable instances. The weakness is classified as CWE-287 (Improper Authentication).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Which versions of Oracle Oracle WebLogic Server are affected?

BRANCHAFFECTEDFIXED
12.x12.2.1.4.0
14.x14.1.1.0.0
14.x14.1.2.0.0

Is CVE-2026-83021 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-83021

  1. Restrict HTTP access to WebLogic instances by blocking or limiting inbound connections at the network perimeter and using allowlists for management interfaces
  2. Isolate affected servers with network segmentation and remove internet exposure for WebLogic administration and application ports
  3. Enable and increase logging and monitoring for unusual HTTP requests and post-authentication activity on WebLogic hosts
  4. Follow Oracle vendor guidance for this issue and prepare to apply vendor-supplied patches or updates as soon as they are released

Frequently asked questions

Is CVE-2026-83021 being actively exploited?

There are no public reports of exploitation of CVE-2026-83021 as of 2026-09-30.

Which Oracle WebLogic Server versions are affected by CVE-2026-83021?

Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0 are listed as affected.

Is there a patch for CVE-2026-83021?

No fixed versions are listed for the affected releases; a vendor patch is not available as of 2026-09-30.

Does CVE-2026-83021 require authentication?

No, the vulnerability can be exploited without authentication; an attacker only needs network access via HTTP to target Oracle WebLogic Server.

References