Junglewise Threat Intelligence

CVE-2026-60439: Oracle Platform Security for Java takeover via Centralized Thirdparty Jars

CVE-2026-60439 · Severity: high · CVSS 8.8 · Published 2026-07-22

Technologies: Oracle Platform Security for Java. Vendors: Oracle.

Executive brief

Oracle Platform Security for Java, a component of Oracle Fusion Middleware used for managing security policies and identities, contains a vulnerability in its centralized third-party libraries. A low-privileged user with network access can exploit this flaw to take full control of the security platform. This could lead to unauthorized access to sensitive data, modification of security settings, and disruption of business operations.

Technical details

This vulnerability exists within the Centralized Thirdparty Jars component of Oracle Platform Security for Java (part of Fusion Middleware). It is classified as easily exploitable, requiring only low-privileged authentication and network access via HTTP. While the specific CWE is not detailed in the advisory, the impact is a complete compromise of Confidentiality, Integrity, and Availability (takeover) of the affected component. The issue affects versions 12.2.1.4.0 and 14.1.2.0.0. Users should refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-22: disclosed
  • 2026-07-22: advisory

References

Related threats