Oracle WebLogic Server Remote Code Execution Vulnerability

Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related to CVE-2020-14750.

Published 26 Aug 2026Updated 26 Aug 202639 sources
CVSS 0.0 ✓ VERIFIED REFERENCE△ CISA KEV

What happened

Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related to CVE-2020-14750.

Affected versions

WebLogic Server: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
Exploit-DB 49479Oracle WebLogic Server 12.2.1.0 - RCE (Unauthenticated)CHackA01012021-01-26VerifiedPoC-in-GitHub · zhzyker/exphubExphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340★ 4290zhzyker2020-04-01CandidatePoC-in-GitHub · jas502n/CVE-2020-14882CVE-2020–14882、CVE-2020–14883★ 287jas502n2020-10-28CandidatePoC-in-GitHub · s1kr10s/CVE-2020-14882CVE-2020–14882 by Jang★ 29s1kr10s2020-10-28CandidatePoC-in-GitHub · XTeam-Wing/CVE-2020-14882CVE-2020-14882 Weblogic-Exp★ 17XTeam-Wing2020-10-29CandidatePoC-in-GitHub · 0thm4n3/cve-2020-14882Bash script to exploit the Oracle's Weblogic Unauthenticated Remote Command Execution - CVE-2020-14882★ 20thm4n32020-10-29CandidatePoC-in-GitHub · wsfengfan/cve-2020-14882CVE-2020-14882 EXP 回显★ 7wsfengfan2020-10-29CandidatePoC-in-GitHub · alexfrancow/CVE-2020-14882★ 0alexfrancow2020-10-30CandidatePoC-in-GitHub · GGyao/CVE-2020-14882_POCCVE-2020-14882批量验证工具。★ 12GGyao2020-10-31CandidatePoC-in-GitHub · ludy-dev/Weblogic_Unauthorized-bypass-RCE(CVE-2020-14882) Oracle Weblogic Unauthorized bypass RCE test script★ 8ludy-dev2020-11-01CandidatePoC-in-GitHub · GGyao/CVE-2020-14882_ALLCVE-2020-14882_ALL综合利用工具,支持命令回显检测、批量命令回显、外置xml无回显命令执行等功能。★ 144GGyao2020-11-03CandidatePoC-in-GitHub · ovProphet/CVE-2020-14882-checkerCVE-2020-14882 detection script★ 1ovProphet2020-11-03CandidatePoC-in-GitHub · NS-Sp4ce/CVE-2020-14882CVE-2020-14882/14883/14750★ 19NS-Sp4ce2020-11-04CandidatePoC-in-GitHub · mmioimm/cve-2020-14882★ 3mmioimm2020-11-05CandidatePoC-in-GitHub · QmF0c3UK/CVE-2020-14882★ 7QmF0c3UK2020-11-09CandidatePoC-in-GitHub · murataydemir/CVE-2020-14882[CVE-2020-14882] Oracle WebLogic Server Authentication Bypass★ 3murataydemir2020-11-09CandidatePoC-in-GitHub · Ormicron/CVE-2020-14882-GUI-Test基于qt的图形化CVE-2020-14882漏洞回显测试工具.★ 2Ormicron2020-11-11CandidatePoC-in-GitHub · corelight/CVE-2020-14882-weblogicRCEDetection of RCE in Oracle's WebLogic Server CVE-2020-14882 / CVE-2020-14750★ 7corelight2020-11-12CandidatePoC-in-GitHub · xfiftyone/CVE-2020-14882★ 5xfiftyone2020-11-12CandidatePoC-in-GitHub · adm1in/CodeTestCodeTest信息收集和漏洞利用工具,可在进行渗透测试之时方便利用相关信息收集脚本进行信息的获取和验证工作,漏洞利用模块可选择需要测试的漏洞模块,或者选择所有模块测试,包含CVE-2020-14882, CVE-2020-2555等,可自己收集脚本后按照模板进行修改。★ 13adm1in2020-12-30CandidatePoC-in-GitHub · pwn3z/CVE-2020-14882-WebLogic★ 0pwn3z2021-01-29CandidatePoC-in-GitHub · milo2012/CVE-2020-14882CVE-2020-14882★ 8milo20122021-02-25CandidatePoC-in-GitHub · kk98kk0/CVE-2020-14882CVE-2020-14882部署冰蝎内存马★ 3kk98kk02021-03-31CandidatePoC-in-GitHub · exploitblizzard/CVE-2020-14882-WebLogicCheck YouTube - https://youtu.be/O0ZnLXRY5Wo★ 3exploitblizzard2021-05-10CandidatePoC-in-GitHub · qianniaoge/CVE-2020-14882_Exploit_Gui★ 0qianniaoge2021-05-25CandidatePoC-in-GitHub · N0Coriander/CVE-2020-14882-14883结合14882的未授权访问漏洞,通过14883可远程执行任意代码★ 2N0Coriander2021-07-03CandidatePoC-in-GitHub · nik0nz7/CVE-2020-14882★ 0nik0nz72023-04-11CandidatePoC-in-GitHub · Root-Shells/CVE-2020-14882CVE-2020-14882 rewritten in PowerShell★ 0Root-Shells2023-04-28CandidatePoC-in-GitHub · Danny-LLi/CVE-2020-14882This script allows for remote code execution (RCE) on Oracle WebLogic Server★ 2Danny-LLi2023-07-17CandidatePoC-in-GitHub · LucasPDiniz/CVE-2020-14882Takeover of Oracle WebLogic Server★ 0LucasPDiniz2023-11-09CandidatePoC-in-GitHub · xMr110/CVE-2020-14882★ 0xMr1102024-02-04CandidatePoC-in-GitHub · zesnd/CVE-2020-14882-POC★ 0zesnd2024-12-21CandidatePoC-in-GitHub · AleksaZatezalo/CVE-2020-14882★ 0AleksaZatezalo2024-12-26CandidatePoC-in-GitHub · KKC73/weblogic-cve-2020-14882This is a repository that aims to provide research material on CVE-2020-14882 as part of a project in partial fullfilment of ACS EDU Program.★ 0KKC732025-01-17CandidatePoC-in-GitHub · b1g-b33f/CVE-2020-14882PoC for testing if a target is vulnerable to RCE★ 1b1g-b33f2025-12-10CandidatePoC-in-GitHub · VelesSecurity/CVE-2020-14882-WebLogic-AnalysisTechnical analysis and clean Java Thread Echo PoC for Oracle WebLogic Server vulnerability chain.★ 0VelesSecurity2026-08-18CandidatePoC-in-GitHub · hyderpwn/weblogicOracle WebLogic Console unauthenticated auth bypass + RCE exploit (CVE-2020-14882 / CVE-2020-14750)★ 0hyderpwn2026-08-27Candidate