CVE-2026-70748: pre-auth remote code execution in Oracle Oracle WebLogic Server

An unauthenticated attacker with network access can remotely compromise Oracle WebLogic Server and achieve full takeover; the flaw is tracked as CVE-2026-70748. Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. The vulnerability is reachable over network protocols T3 and IIOP and requires no valid credentials or user interaction to exploit.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00483
CWE
CWE-287
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: this is a pre-auth remote compromise of an internet-reachable service with a CVSS 9.8 rating, so prioritize isolating and restricting T3/IIOP exposure immediately and apply vendor fixes when released.

What is CVE-2026-70748?

An unauthenticated attacker with network access can remotely compromise Oracle WebLogic Server and achieve full takeover; the flaw is tracked as CVE-2026-70748. Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. The vulnerability is reachable over network protocols T3 and IIOP and requires no valid credentials or user interaction to exploit. The weakness is classified as CWE-287 (Improper Authentication).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Oracle Oracle WebLogic Server are affected?

BRANCHAFFECTEDFIXED
12.x12.2.1.4.0
14.x14.1.1.0.0
14.x14.1.2.0.0
15.x15.1.1.0.0

Is CVE-2026-70748 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-70748

  1. Restrict network exposure: block or limit access to T3 and IIOP ports at the perimeter and between network segments.
  2. Apply vendor guidance: follow Oracle’s mitigation advisory and deploy recommended configuration changes as published.
  3. Monitor and hunt: review WebLogic logs and network telemetry for unusual T3/IIOP connections and signs of remote code execution.
  4. Plan patching: prepare to install vendor fixes when they become available and test updates in staging before production.

Frequently asked questions

Is CVE-2026-70748 being actively exploited?

There are no public reports of CVE-2026-70748 being exploited as of 2026-09-30.

Which Oracle WebLogic Server versions are affected by CVE-2026-70748?

Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0 are listed as affected.

Is there a patch for CVE-2026-70748?

No vendor-fixed versions are listed; a patch is not available as of 2026-09-30, so follow Oracle’s interim guidance and mitigations.

Does CVE-2026-70748 require authentication?

No, exploitation of CVE-2026-70748 does not require authentication and is reachable via network access to T3 or IIOP.

References