
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-70756 is a critical improper authentication vulnerability in the Core component of Oracle WebLogic Server, part of Oracle Fusion Middleware. It affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. An unauthenticated attacker with network access via the T3 or IIOP protocols can exploit this vulnerability to achieve complete takeover of the affected server. It was disclosed and patched on September 15, 2026, as part of Oracle's Critical Security Patch Update (CSPU). The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) (Oracle Advisory).
The vulnerability is classified under CWE-287 (Improper Authentication) and CWE-306 (Missing Authentication for Critical Function), indicating that the WebLogic Server Core component fails to properly enforce authentication for critical operations accessible via the T3 and IIOP protocols. T3 and IIOP are Java-based remote communication protocols natively supported by WebLogic and commonly exposed on default ports (7001/7002). An unauthenticated remote attacker can send specially crafted requests over these protocols to bypass authentication controls and interact with privileged server functions. No privileges or user interaction are required, and attack complexity is low, making this vulnerability highly automatable (Oracle Advisory).
Successful exploitation results in complete takeover of the Oracle WebLogic Server, with high impact to confidentiality, integrity, and availability. An attacker can read sensitive application data and credentials, modify server configuration and deployed applications, deploy malicious code (e.g., web shells), and disrupt service availability. Given WebLogic's typical role as an enterprise application server, compromise could enable lateral movement into backend databases, connected enterprise systems, and internal networks (Oracle Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Oracle Advisory). The vulnerability has an EPSS score of approximately 0.0045 (0.45%), reflecting a currently low but non-negligible probability of exploitation in the near term. The vulnerability is marked as automatable by NVD SSVC analysis, meaning exploitation can be scripted at scale. It has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog at this time. No specific threat actor attribution has been reported.
server.log) showing unauthenticated access attempts or errors related to Core component authentication; access log entries with malformed or oversized T3/IIOP payloads./domains/<domain>/servers/<server>/tmp/, /autodeploy/).cmd.exe, /bin/bash, curl, wget, powershell); unexpected Java processes executing system commands.Oracle has released patches for all affected versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0) as part of the September 2026 Critical Security Patch Update. Organizations should apply the patch immediately given the critical severity and unauthenticated attack vector. As a temporary workaround, restrict network access to T3 and IIOP ports (typically 7001/7002) to trusted hosts only using firewall rules or WebLogic's built-in connection filter. Oracle strongly recommends against relying on network-level mitigations as a long-term solution (Oracle Advisory).
The vulnerability was noted in Oracle's September 2026 CSPU, which addressed 673 vulnerabilities across Oracle product families. Security analysis from Waratek and CyCognito highlighted CVE-2026-70756 as a high-priority finding within the patch update, emphasizing the risk posed by unauthenticated T3/IIOP access. AUSCERT issued a bulletin (ASB-2026.0229) covering the Oracle CSPU, and the vulnerability was discussed briefly on social media platforms including Mastodon. Community sentiment reflects urgency around patching given the historical pattern of WebLogic T3/IIOP vulnerabilities being rapidly weaponized (Oracle Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."