CVE-2026-70748
largeUnauthenticated Takeover of Oracle WebLogic Server via T3/IIOP (CVSS 9.8)
CVE-2026-70748 is a critical (CVSS 9.8) vulnerability in the Core component of Oracle WebLogic Server, part of Oracle Fusion Middleware, that allows an unauthenticated remote attacker with network access to fully compromise the server. The flaw is triggered by sending crafted requests to the WebLogic T3 or IIOP protocol listeners, which are commonly enabled for Java client and RMI communications. A successful attack results in a complete takeover of Oracle WebLogic Server with high impact on confidentiality, integrity, and availability. All currently supported releases are affected — 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 — so any deployment exposing T3/IIOP to untrusted networks is at risk. The issue is not on CISA's KEV catalog and no public proof-of-concept is known, though remotely exploitable WebLogic flaws of this severity are frequently targeted once patch details circulate.
What to do: Apply the Oracle Critical Patch Update that fixes CVE-2026-70748 to all WebLogic installations running 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, or 15.1.1.0.0. Until patched, block or strictly allow-list T3 and IIOP traffic at perimeter firewalls, and disable those listeners on servers that do not need them. Check any host with an exposed T3/IIOP port for indicators of compromise, such as unexpected WAR deployments, new administrative users, or modified server startup scripts.
| Oracle WebLogic Server (Oracle Fusion Middleware, component: Core) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Weakness
- CWE-287, CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.