Junglewise Threat Intelligence

CVE-2026-61246: Oracle Platform Security for Java takeover via Centralized Thirdparty Jars

CVE-2026-61246 · Severity: high · CVSS 8.8 · Published 2026-07-22

Executive brief

A vulnerability exists in Oracle Platform Security for Java, a component used to manage security policies and identities within Oracle Fusion Middleware environments. An attacker with basic user access to the network can exploit this flaw to take full control of the security platform. This could lead to unauthorized access to sensitive data, modification of security settings, or disruption of integrated business applications.

Technical details

This vulnerability affects the Centralized Thirdparty Jars component within Oracle Platform Security for Java (Oracle Fusion Middleware). It is classified as easily exploitable, requiring only low-privileged user credentials and network access via HTTP. The flaw allows an attacker to achieve a complete takeover of the affected component, impacting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. While the specific CWE is not detailed in the advisory, the impact is rated as a full compromise of the security framework.

Affected products

  • Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-22: disclosed
  • 2026-07-22: advisory: Published in Oracle Critical Patch Update Advisory - July 2026

References

Related threats