Junglewise Threat Intelligence

CVE-2026-60369: Oracle Platform Security for Java compromise in Centralized Thirdparty Jars

CVE-2026-60369 · Severity: critical · CVSS 9.9 · Published 2026-07-22

Technologies: Oracle Platform Security for Java. Vendors: Oracle.

Executive brief

Oracle Platform Security for Java, a component of Oracle Fusion Middleware used to manage security policies and identities, contains a critical vulnerability in its third-party library components. A low-privileged user with network access can exploit this flaw to take full control of the security platform. Because this component provides security services to other applications, a successful attack could lead to a total compromise of multiple connected business systems and data.

Technical details

This vulnerability exists within the Centralized Thirdparty Jars component of Oracle Platform Security for Java. It is classified as easily exploitable, requiring only low-privileged user credentials and network access via HTTP. The exploit results in a scope change (CVSS S:C), meaning the impact extends beyond the immediate security component to other parts of the Oracle Fusion Middleware environment. Successful exploitation grants the attacker full control over the confidentiality, integrity, and availability of the affected system. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users should refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation.

Affected products

  • Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-22: advisory: Initial disclosure by Oracle

References

Related threats