ZeroHour

CVE-2026-70748

large

Unauthenticated Takeover of Oracle WebLogic Server via T3/IIOP (CVSS 9.8)

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-70748 is a critical (CVSS 9.8) vulnerability in the Core component of Oracle WebLogic Server, part of Oracle Fusion Middleware, that allows an unauthenticated remote attacker with network access to fully compromise the server. The flaw is triggered by sending crafted requests to the WebLogic T3 or IIOP protocol listeners, which are commonly enabled for Java client and RMI communications. A successful attack results in a complete takeover of Oracle WebLogic Server with high impact on confidentiality, integrity, and availability. All currently supported releases are affected — 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 — so any deployment exposing T3/IIOP to untrusted networks is at risk. The issue is not on CISA's KEV catalog and no public proof-of-concept is known, though remotely exploitable WebLogic flaws of this severity are frequently targeted once patch details circulate.

What to do: Apply the Oracle Critical Patch Update that fixes CVE-2026-70748 to all WebLogic installations running 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, or 15.1.1.0.0. Until patched, block or strictly allow-list T3 and IIOP traffic at perimeter firewalls, and disable those listeners on servers that do not need them. Check any host with an exposed T3/IIOP port for indicators of compromise, such as unexpected WAR deployments, new administrative users, or modified server startup scripts.

Affected
Oracle WebLogic Server (Oracle Fusion Middleware, component: Core)
Estimated exposure
large≈ tens of thousands of internet-exposed WebLogic instances, plus a larger unmeasured internal enterprise population — Public internet-wide scans have historically shown on the order of tens of thousands of WebLogic servers with T3/admin ports reachable, and since every supported version listed is affected, a substantial share of that exposed population is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Weakness
CWE-287, CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.