Junglewise Threat Intelligence

CVE-2026-60455: Oracle Platform Security for Java takeover via Centralized Thirdparty Jars

CVE-2026-60455 · Severity: high · CVSS 8.8 · Published 2026-07-22

Technologies: Oracle Platform Security for Java. Vendors: Oracle.

Executive brief

Oracle Platform Security for Java, a component of Oracle Fusion Middleware used for managing security policies and identities, contains a vulnerability in its centralized third-party libraries. A remote attacker with low-level user credentials can exploit this flaw over the network to gain full control of the security platform. This could lead to unauthorized access to sensitive data, modification of security settings, and disruption of services relying on the middleware.

Technical details

A vulnerability exists in the Centralized Thirdparty Jars component of Oracle Platform Security for Java (part of Oracle Fusion Middleware). The flaw is easily exploitable by a remote attacker with low privileges (PR:L) via the HTTP protocol. Successful exploitation allows for a complete compromise of the product, impacting confidentiality, integrity, and availability (C:H/I:H/A:H). Affected versions include 12.2.1.4.0 and 14.1.2.0.0. While the specific CWE is not detailed in the advisory, the impact is described as a full system takeover.

Affected products

  • Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-22: disclosed: Initial publication of CVE-2026-60455
  • 2026-07-22: advisory: Oracle Critical Patch Update July 2026 released

References

Related threats