EIP-2026-102433
PRE-CVEWebLogic Server 10.3.6.0.0 / 12.1.3.0.0 / 12.2.1.3.0 / 12.2.1.4.0 / 14.1.1.0.0 - Unauthenticated RCE via GET request
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102433. PoCs published by Mohammed Althibyani.
AI-analyzed exploit summary This exploit leverages an unauthenticated RCE vulnerability in Oracle WebLogic Server via a crafted GET request. It abuses path traversal and MVEL expression injection to execute arbitrary commands.
Description
WebLogic Server 10.3.6.0.0 / 12.1.3.0.0 / 12.2.1.3.0 / 12.2.1.4.0 / 14.1.1.0.0 - Unauthenticated RCE via GET request
Exploits (1)
exploitdb
WORKING POC
by Mohammed Althibyani · pythonwebappsjava
https://www.exploit-db.com/exploits/48971
This exploit leverages an unauthenticated RCE vulnerability in Oracle WebLogic Server via a crafted GET request. It abuses path traversal and MVEL expression injection to execute arbitrary commands.
Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target:
Oracle WebLogic Server 10.3.6.0.0 / 12.1.3.0.0 / 12.2.1.3.0 / 12.2.1.4.0 / 14.1.1.0.0
No auth needed
Prerequisites:
Network access to the WebLogic Server console · Target server must be vulnerable to CVE-2020-14882
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026