Executive brief
Oracle Fusion Middleware Control is a management interface for Oracle's middleware infrastructure. A vulnerability allows authenticated users with low privilege to gain complete control over the system, compromising confidentiality, integrity, and availability of critical middleware management functions.
Technical details
This is an authentication or authorization bypass vulnerability in Oracle Fusion Middleware Control's Framework component. The vulnerability is easily exploitable by a low-privileged attacker with network access via HTTP, requiring only low privileges and no user interaction. Successful exploitation allows an attacker to achieve complete compromise of the Fusion Middleware Control system (taking over its functions and potentially accessing or modifying managed resources). Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Oracle has issued an advisory with details available through their official security alerts portal.
Affected products
- Oracle Fusion Middleware Control 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed