Junglewise Threat Intelligence

CVE-2026-70748: Oracle WebLogic Server remote code execution in Core

CVE-2026-70748 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Executive brief

Oracle WebLogic Server is a Java application server used to host enterprise applications and services. A critical vulnerability in its core component allows remote attackers without credentials to gain complete control over the server, enabling them to steal data, modify applications, or disrupt business operations. The flaw is easily exploitable over the network and requires no user interaction.

Technical details

This vulnerability in Oracle WebLogic Server's Core component allows unauthenticated remote code execution via the T3 and IIOP protocols. The flaw is easily exploitable with no authentication required, no complex configuration, and no user interaction necessary. Attackers with network access can exploit this to achieve complete compromise of the WebLogic Server, resulting in confidentiality, integrity, and availability impacts. Affected versions are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Patches should be available through Oracle's standard security update channels.

Affected products

  • Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats