CVE-2020-2551

CRITICAL KEV NUCLEI

Oracle WebLogic Server <12.2.1.4 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2020-2551 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 16, 2023. EIP tracks 11 public exploits from researchers including 0xn0ne, Y4er, hktalent. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository contains a WebLogic vulnerability scanner that checks for multiple CVEs, including CVE-2018-2628. It is a Python-based tool designed to detect vulnerabilities in Oracle WebLogic Server by sending crafted requests and analyzing responses.

Description

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Exploits (11)

nomisec SCANNER 2,072 stars
by 0xn0ne · remote
https://github.com/0xn0ne/weblogicScanner

This repository contains a WebLogic vulnerability scanner that checks for multiple CVEs, including CVE-2018-2628. It is a Python-based tool designed to detect vulnerabilities in Oracle WebLogic Server by sending crafted requests and analyzing responses.

Classification
Scanner 95%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server
No auth needed
Prerequisites: Network access to the target WebLogic Server · Python 3.6 or higher
devstral-2 · analyzed Feb 15, 2026 Full analysis →
nomisec WORKING POC 340 stars
by Y4er · remote
https://github.com/Y4er/CVE-2020-2551

This repository contains a working exploit for CVE-2020-2551, a deserialization vulnerability in Oracle WebLogic Server. The exploit leverages IIOP/T3 protocol to achieve remote code execution by sending a malicious serialized object to a vulnerable WebLogic server.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server 10.3.6
No auth needed
Prerequisites: Access to a vulnerable WebLogic Server instance · Java environment matching the target's JDK version · Network access to the target server on the IIOP/T3 port (typically 7001) · A malicious RMI server to host the payload
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec SCANNER 211 stars
by hktalent · remote
https://github.com/hktalent/CVE-2020-2551

This repository contains a Python script to scan for CVE-2020-2551, a vulnerability in Oracle WebLogic Server. The script sends a GIOP packet to check for the presence of the vulnerability and supports multi-threaded scanning.

Classification
Scanner 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Oracle WebLogic Server
No auth needed
Prerequisites: Network access to the target WebLogic Server
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 92 stars
by zzwlpx · poc
https://github.com/zzwlpx/weblogicPoc

This repository contains a working exploit PoC for CVE-2020-2551, a WebLogic IIOP deserialization vulnerability. The exploit leverages RMI to achieve remote code execution by deserializing a malicious payload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server 10.3.6
No auth needed
Prerequisites: Access to WebLogic server with IIOP enabled · RMI server hosting malicious payload · Matching JDK version for compilation
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP 80 stars
by jas502n · poc
https://github.com/jas502n/CVE-2020-2551

This repository contains a writeup and demonstration for CVE-2020-2551, a deserialization vulnerability in Oracle WebLogic Server that allows remote code execution via IIOP. The README includes screenshots and a GIF demonstrating the exploit but does not contain actual exploit code.

Classification
Writeup 90%
Attack Type
Deserialization
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server
No auth needed
Prerequisites: Network access to the target WebLogic Server · IIOP protocol enabled on the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 22 stars
by Dido1960 · poc
https://github.com/Dido1960/Weblogic-CVE-2020-2551-To-Internet

This repository contains a Python-based exploit for CVE-2020-2551, a deserialization vulnerability in Oracle WebLogic Server. The exploit sends crafted T3 protocol packets to trigger remote code execution by leveraging a malicious RMI endpoint.

Classification
Working Poc 95%
Attack Type
Deserialization
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server (versions affected by CVE-2020-2551)
No auth needed
Prerequisites: Network access to the target WebLogic Server · T3 protocol enabled on the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec SCANNER 1 stars
by abbarhissarh · poc
https://github.com/abbarhissarh/CVE-Exploit

The repository contains a Python script that scans for CVE-2020-2551 by sending a crafted GIOP request to detect vulnerable Oracle WebLogic servers. It does not include exploit code for achieving RCE but confirms the presence of the vulnerability.

Classification
Scanner 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Oracle WebLogic Server
No auth needed
Prerequisites: network access to target WebLogic server
devstral-2 · analyzed Apr 10, 2026 Full analysis →
nomisec SCANNER 1 stars
by ar2o3 · poc
https://github.com/ar2o3/CVE-Exploit

This repository contains a Python script designed to scan for CVE-2020-2551, a vulnerability in Oracle WebLogic Server. The script sends a crafted GIOP packet to check for the presence of the vulnerability and supports both single URL and bulk checking via stdin.

Classification
Scanner 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Oracle WebLogic Server
No auth needed
Prerequisites: Network access to the target WebLogic Server
devstral-2 · analyzed Feb 16, 2026 Full analysis →
gitlab WORKING POC
by milo2012 · poc
https://gitlab.com/milo2012/cve-2020-2551

This repository contains a functional exploit for CVE-2020-2551, a deserialization vulnerability in Oracle WebLogic Server's IIOP protocol. The exploit sends a crafted LocateRequest and bind_any payload to trigger remote code execution via a malicious JNDI lookup.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server (10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0)
No auth needed
Prerequisites: Target with IIOP protocol enabled · RMI server hosting malicious payload
devstral-2 · analyzed Feb 23, 2026 Full analysis →
nomisec WORKING POC
by DaMinGshidashi · poc
https://github.com/DaMinGshidashi/CVE-2020-2551

This repository contains a proof-of-concept exploit for CVE-2020-2551, a deserialization vulnerability in Oracle WebLogic Server. It includes scripts to set up a vulnerable environment and tools to generate and send malicious payloads.

Classification
Working Poc 90%
Attack Type
Deserialization
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server 10.3.6 and 12.1.3
No auth needed
Prerequisites: Vulnerable WebLogic Server instance · Network access to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
vulncheck_xdb SCANNER
remote
https://github.com/0xAbbarhSF/CVE-Exploit

The repository contains a Python script that scans for CVE-2020-2551 by sending a crafted GIOP request to detect vulnerable Oracle WebLogic servers. It does not include exploit code for achieving RCE but confirms the presence of the vulnerability.

Classification
Scanner 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Oracle WebLogic Server
No auth needed
Prerequisites: network access to target WebLogic server
devstral-2 · analyzed Feb 25, 2026 Full analysis →

Nuclei Templates (1)

Oracle WebLogic Server - Remote Code Execution
CRITICALby dwisiswant0
Shodan: http.title:"oracle peoplesoft sign-in" || product:"oracle weblogic"
FOFA: title="oracle peoplesoft sign-in"

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.9441
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2023-11-16
VulnCheck KEV 2023-06-02
InTheWild.io 2021-12-04
ENISA EUVD EUVD-2020-22344
Status published
Products (4)
oracle/weblogic_server 10.3.6.0.0
oracle/weblogic_server 12.1.3.0.0
oracle/weblogic_server 12.2.1.3.0
oracle/weblogic_server 12.2.1.4.0
Published Jan 15, 2020
KEV Added Nov 16, 2023
Tracked Since Feb 18, 2026