Junglewise Threat Intelligence

CVE-2026-60373: Oracle Platform Security for Java compromise in Centralized Thirdparty Jars

CVE-2026-60373 · Severity: high · CVSS 8.8 · Published 2026-07-22

Technologies: Oracle Platform Security for Java. Vendors: Oracle.

Executive brief

Oracle Platform Security for Java, a component of Oracle Fusion Middleware used for managing security policies and identities, contains a vulnerability in its third-party library components. An attacker with basic user credentials can exploit this over the network to gain full control of the security platform. This could lead to unauthorized access to sensitive data, modification of security settings, or disruption of services relying on Fusion Middleware.

Technical details

A vulnerability exists in the Centralized Thirdparty Jars component of Oracle Platform Security for Java (Oracle Fusion Middleware). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. While the specific CWE is not identified in the advisory, the impact is rated as high for confidentiality, integrity, and availability, potentially leading to a complete takeover of the affected component. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users should refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-22: disclosed: Initial disclosure by Oracle via NVD and CPU advisory.

References

Related threats