Executive brief
Oracle Platform Security for Java, a core component of Oracle Fusion Middleware used for managing security policies and identities, contains a critical vulnerability. An unauthenticated attacker can exploit this over the network to gain full control of the security platform. Because this component provides security services to other applications, a successful attack could lead to a total compromise of the entire middleware environment and any connected business data.
Technical details
A critical vulnerability exists in the Oracle Platform Security for Java (part of Oracle Fusion Middleware) within the Centralized Thirdparty Jars component. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. While the root cause is within the security platform's third-party libraries, the vulnerability has a 'Scope Change' (S:C), meaning an exploit can impact other products and components beyond the initial security layer. Successful exploitation can result in a complete takeover of the Oracle Platform Security for Java instance, impacting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.0.0.
Affected products
- Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-22: disclosed
- 2026-07-22: advisory: Oracle July 2026 Critical Patch Update