Junglewise Threat Intelligence

CVE-2026-60368: Oracle Platform Security for Java takeover via SOAP in Centralized Thirdparty Jars

CVE-2026-60368 · Severity: high · CVSS 8.8 · Published 2026-07-22

Technologies: Oracle Platform Security for Java. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle Platform Security for Java, a component of Oracle Fusion Middleware used to manage security policies and identities across Java applications. An attacker with low-level access to the network can exploit this flaw to take full control of the security platform. This could lead to unauthorized access to sensitive data, modification of security settings, or disruption of business services.

Technical details

This vulnerability affects the Centralized Thirdparty Jars component within Oracle Platform Security for Java (versions 12.2.1.4.0 and 14.1.2.0.0). It is classified as an easily exploitable flaw that can be triggered by a low-privileged attacker with network access via the SOAP protocol. Successful exploitation allows for a complete takeover of the Oracle Platform Security for Java environment, impacting confidentiality, integrity, and availability. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-22: disclosed
  • 2026-07-22: advisory: Oracle July 2026 Critical Patch Update released

References

Related threats