Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-70757
Oracle WebLogic Server vulnerability analysis and mitigation

Overview

CVE-2026-70757 is a critical improper authentication vulnerability in the Core component of Oracle WebLogic Server, part of Oracle Fusion Middleware. It affects supported versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The vulnerability allows unauthenticated attackers with network access via the T3 or IIOP protocols to fully compromise the affected server. It was disclosed and patched on September 15, 2026, as part of Oracle's Critical Security Patch Update (CSPU). It carries a CVSS v3.1 base score of 9.8 (Critical) (Oracle Advisory).

Technical details

The vulnerability is classified under CWE-287 (Improper Authentication) and CWE-306 (Missing Authentication for Critical Function), indicating that critical server functions accessible via the T3 and IIOP protocols lack adequate authentication controls. T3 and IIOP are WebLogic-specific protocols used for remote Java object communication (RMI/CORBA), and they have historically been vectors for deserialization and authentication bypass attacks in WebLogic environments. An unauthenticated attacker with network-level access to the WebLogic listen port (typically 7001/7002) can exploit this flaw without any user interaction or special privileges, making it highly automatable. No public proof-of-concept or technical write-up has been identified at the time of disclosure (Oracle Advisory).

Impact

Successful exploitation results in a complete takeover of the Oracle WebLogic Server, with full impact to confidentiality, integrity, and availability. An attacker can execute arbitrary code, read or modify sensitive data and configurations, and disrupt service availability — effectively gaining the same level of access as the WebLogic service account. Given WebLogic's typical role as an enterprise application server, compromise could enable lateral movement into connected databases, backend services, and internal networks (Oracle Advisory).

Exploitability

As of the disclosure date (September 15, 2026), there is no evidence of public proof-of-concept code or active in-the-wild exploitation. The vulnerability is classified as "automatable" by NVD SSVC analysis, meaning it can be exploited at scale without manual interaction. The EPSS score is approximately 0.0033 (0.33%), reflecting a currently low but non-negligible probability of exploitation in the near term. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time (Oracle Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible Oracle WebLogic Server instances running versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, or 15.1.1.0.0 using tools such as Shodan, Censys, or Nmap targeting default WebLogic ports (7001, 7002, 9002).
  2. Protocol targeting: Confirm that the T3 or IIOP protocol listener is active on the target server, as these are the required attack vectors for this vulnerability.
  3. Authentication bypass: Send a crafted T3 or IIOP request that exploits the missing or improper authentication check in the WebLogic Core component, bypassing authentication without providing valid credentials.
  4. Code execution / takeover: Leverage the unauthenticated access to execute arbitrary code on the server (e.g., via remote class loading or deserialization), deploy a web shell, or manipulate server configurations to establish persistence and enable lateral movement.

Note: No public PoC or detailed technical write-up is available at this time; the above steps are based on the vulnerability's characteristics and historical T3/IIOP attack patterns against WebLogic (Oracle Advisory).

Indicators of compromise

  • Network: Unexpected or anomalous inbound connections to WebLogic T3/IIOP ports (default: 7001, 7002, 9002) from untrusted or external IP addresses; unusual outbound connections from the WebLogic server process to unknown external hosts.
  • Logs: WebLogic server logs (server.log) showing unauthenticated or failed authentication attempts on T3/IIOP endpoints; unexpected class loading or deserialization events in application logs.
  • File System: Presence of new or unexpected files (e.g., JSP web shells, JAR files) in the WebLogic deployment directories (/domains/<domain>/servers/<server>/tmp/, /autodeploy/).
  • Process: Unusual child processes spawned by the WebLogic JVM process (e.g., cmd.exe, /bin/bash, curl, wget, powershell); unexpected scheduled tasks or cron jobs created under the WebLogic service account.

Mitigation and workarounds

Oracle has released patches for all affected versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0) as part of the September 2026 Critical Security Patch Update; applying these patches immediately is the recommended remediation (Oracle Advisory). As a temporary workaround, restrict network access to the WebLogic T3 and IIOP protocol ports (typically 7001, 7002, 9002) to trusted IP addresses only using firewall rules or network ACLs. Oracle also recommends implementing network segmentation to limit exposure of WebLogic Server instances to untrusted networks. Organizations should ensure they are running actively supported versions eligible for security patches under Oracle's Lifetime Support Policy.

Community reactions

The vulnerability was covered in Oracle's September 2026 CSPU, which addressed 673 vulnerabilities across Oracle product families — a release scale that drew attention from the security community. Waratek published an analysis of the September 2026 Oracle CSPU (Waratek Analysis), and AusCERT issued a security bulletin (ASB-2026.0229) referencing the advisory. Beyond Machines also noted the breadth of the patch release. No specific high-profile researcher commentary or social media discussion focused exclusively on CVE-2026-70757 has been identified at this time.

Additional resources


SourceThis report was generated using AI

Related Oracle WebLogic Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-83021CRITICAL10
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesSep 15, 2026
CVE-2026-83038CRITICAL9.9
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesSep 15, 2026
CVE-2026-70757CRITICAL9.8
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesSep 15, 2026
CVE-2026-70756CRITICAL9.8
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesSep 15, 2026
CVE-2026-70748CRITICAL9.8
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesSep 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management