External risk intelligence

Oracle WebLogic Server Proxy Plug-in Data Integrity and Confidentiality Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-60365

The affected component is a WebLogic Server Proxy Plug-in, which by design sits at the edge of the network to handle incoming HTTP/HTTPS traffic between third-party web servers and backend systems. As a gateway-level component intended for public-facing web infrastructure, it is inherently exposed to the internet in common deployment patterns.

Missing Authentication

Oracle Http Server

12.2.1.4.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in Oracle WebLogic Server's Proxy Plug-in, a component that handles incoming web traffic. If exploited, an attacker could gain unauthorized access to sensitive data or modify critical information within the affected systems. The main concern is confirming if this specific component is in use and potentially exposed.

  • WebLogic plug-in allows unauthorized data access.
  • Critical data modification and access are at risk.
  • Verify if this component is in use.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted network requests over HTTP to a vulnerable Oracle Weblogic Server Proxy Plug-in. Since no authentication is required, an unauthenticated attacker with network access can leverage this exposure. Successful exploitation could lead to unauthorized modification or access to critical data managed by the plug-in, potentially impacting other connected Oracle products.

  • Requires network access, no authentication needed.
  • Triggered by specially crafted HTTP requests.
  • Risk of critical data modification or access.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access could exploit this vulnerability to gain unauthorized access to critical data or modify it within the Oracle Weblogic Server Proxy Plug-in and potentially other connected products. This could lead to unauthorized creation, deletion, or modification of data.

  • Accessible data and critical data at risk.
  • Attacker exploits via network access.
  • Unauthorized data creation, deletion, modification.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given the Oracle Weblogic Server Proxy Plug-in's role in handling external traffic, the platform or infrastructure teams responsible for WebLogic Server deployments are likely accountable. The initial step involves identifying all instances of the affected plug-in, confirming their reachability and criticality to business operations, and then assigning ownership for remediation planning.

  • Platform/Infrastructure teams own the issue.
  • Verify reachability and business criticality first.
  • Plan vendor coordination and phased remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Oracle Weblogic Server Proxy Plug-in?

It is a component of Oracle Fusion Middleware designed to bridge the gap between third-party web servers and backend Oracle WebLogic systems. By acting as an intermediary, it manages and routes incoming HTTP and HTTPS traffic, ensuring requests are correctly handed off to the appropriate application servers.

How does CVE-2026-60365 impact security?

This vulnerability allows an attacker to bypass security controls to interact with data. Because it lacks authentication requirements, it functions as a gateway for unauthorized actors to read, create, modify, or delete critical information accessible through the plug-in, potentially affecting connected systems beyond the plug-in itself.

Do I need to be authenticated to trigger this vulnerability?

No. The flaw does not require an attacker to have legitimate credentials or prior system access. It is triggered by sending specifically crafted HTTP network requests directly to the plug-in. Requests that do not conform to the malicious patterns required to manipulate the plug-in's logic will not trigger the vulnerability.

Is my environment at risk from this CVE?

Halo Surface Signal indicates that because this plug-in is architected to handle traffic at the network edge, it is often internet-facing by design. If your infrastructure uses this component to route external web traffic to backend systems, it is in a position where an attacker could reach it over the network.

What should I do first to address this advisory?

Begin by auditing your infrastructure to locate all instances of the 15.1.1.0.0 version of the plug-in. Determine which instances are reachable from the internet versus those confined to internal networks. Once mapped, assess the business criticality of these systems to prioritize your remediation and patching schedule with your platform or infrastructure teams.

References