Junglewise Threat Intelligence

CVE-2026-83020: Oracle Platform Security for Java remote code execution

CVE-2026-83020 · Severity: critical · CVSS 10 · Published 2026-09-15

Executive brief

Oracle Platform Security for Java is a security component used by Oracle Fusion Middleware to protect applications and data. An unauthenticated attacker can exploit this vulnerability over the network without authentication to take complete control of the affected system, potentially compromising all connected applications and sensitive data.

Technical details

This is a critical vulnerability in Oracle Platform Security for Java (component: Centralized Thirdparty Jars) that allows unauthenticated remote code execution. The vulnerability is easily exploitable via HTTP network access with no authentication or user interaction required, affecting versions 12.2.1.4.0 and 14.1.2.0.0. A successful attack results in complete compromise of Oracle Platform Security for Java, with scope change indicating potential impact to additional connected products. The vulnerability carries a CVSS 3.1 base score of 10.0 with full impacts on confidentiality, integrity, and availability.

Affected products

  • Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats