Junglewise Threat Intelligence

CVE-2026-82994: Oracle Platform Security for Java remote code execution in LDAP

CVE-2026-82994 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Executive brief

Oracle Platform Security for Java is a core security component of Oracle Fusion Middleware that manages authentication and authorization. An unauthenticated attacker on the network can exploit a vulnerability via LDAP to achieve complete compromise of the Platform Security for Java system, resulting in potential takeover of authentication and access controls across dependent Oracle applications.

Technical details

The vulnerability exists in the Centralized Thirdparty Jars component of Oracle Platform Security for Java and is exploitable via LDAP protocol with no authentication required. Affected versions are 12.2.1.4.0 and 14.1.2.0.0. An unauthenticated network attacker can exploit this to achieve remote code execution or full system compromise. The attack has low complexity and requires no user interaction. Patch status should be confirmed through Oracle's official security advisory.

Affected products

  • Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats