Junglewise Threat Intelligence

CVE-2026-70757: Oracle WebLogic Server unauthenticated remote code execution

CVE-2026-70757 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Executive brief

Oracle WebLogic Server is a Java application server used to run enterprise applications and services. An unauthenticated attacker on the network can exploit a vulnerability in the Core component via T3 or IIOP protocols to achieve complete control over the server, enabling takeover of applications and data hosted on it.

Technical details

The vulnerability is a remote code execution flaw in Oracle WebLogic Server's Core component that can be exploited by an unauthenticated attacker with network access via the T3 (Oracle proprietary) or IIOP (Inter-ORB) protocols. No user interaction or authentication is required; the vulnerability is easily exploitable due to low attack complexity. Successful exploitation results in complete compromise of the WebLogic Server, granting an attacker the ability to execute arbitrary code, read/modify data, and disrupt availability. Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Patches or mitigations should be obtained from Oracle's security advisories.

Affected products

  • Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats