CVE-2026-60370 Overview
CVE-2026-60370 is a high-severity vulnerability in Oracle Platform Security for Java, a component of Oracle Fusion Middleware. The flaw resides in the Centralized Thirdparty Jars component and affects supported versions 12.2.1.4.0 and 14.1.2.0.0. A low-privileged attacker with network access over HTTP can exploit the weakness to compromise the product. Successful exploitation results in full takeover of Oracle Platform Security for Java, impacting confidentiality, integrity, and availability.
Critical Impact
Successful attacks result in complete takeover of Oracle Platform Security for Java, exposing sensitive middleware credentials, policies, and identity artifacts.
Affected Products
- Oracle Platform Security for Java 12.2.1.4.0
- Oracle Platform Security for Java 14.1.2.0.0
- Oracle Fusion Middleware deployments using the Centralized Thirdparty Jars component
Discovery Timeline
- 2026-07-22 - CVE CVE-2026-60370 published to NVD
- 2026-07-22 - Last updated in NVD database
- July 2026 - Addressed in the Oracle Security Alert July 2026
Technical Details for CVE-2026-60370
Vulnerability Analysis
Oracle Platform Security for Java (OPSS) provides authentication, authorization, credential storage, and cryptographic services for Oracle Fusion Middleware. The vulnerable Centralized Thirdparty Jars component manages shared third-party libraries used across middleware deployments. An authenticated attacker with low privileges can send crafted HTTP requests to the exposed interfaces to compromise the service. Exploitation is difficult and requires specific conditions to succeed, but the resulting compromise gives an attacker control over identity, credential, and policy operations handled by OPSS.
Root Cause
Oracle has not published detailed root-cause information. The advisory attributes the flaw to the Centralized Thirdparty Jars component within OPSS, which handles shared libraries consumed by middleware services. See the Oracle Security Alert July 2026 for vendor-supplied technical context.
Attack Vector
The attack vector is network-based over HTTP. The attacker must already hold low-level privileges within the environment and must overcome conditions that make exploitation difficult. No user interaction is required, and the scope remains unchanged. A successful attack yields high impact to confidentiality, integrity, and availability, effectively allowing full takeover of Oracle Platform Security for Java.
No public exploit code or proof of concept has been observed for this issue. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.
Detection Methods for CVE-2026-60370
Indicators of Compromise
- Unexpected authenticated HTTP requests targeting OPSS endpoints or Centralized Thirdparty Jars management interfaces.
- Anomalous read or write activity against OPSS credential stores, policy stores, or keystore artifacts.
- New or modified third-party JAR files in the centralized library location outside of maintenance windows.
Detection Strategies
- Enable and review audit logs for Oracle Fusion Middleware and OPSS, focusing on privileged operations performed by low-privileged accounts.
- Correlate WebLogic and OPSS access logs with identity provider logs to detect abnormal reuse of low-privilege accounts against OPSS interfaces.
- Compare deployed third-party JAR hashes against a known-good baseline to identify unauthorized replacement or tampering.
Monitoring Recommendations
- Alert on any modification to files under the OPSS domain and centralized JAR directories.
- Monitor administrative HTTP endpoints of Fusion Middleware for repeated failed authorization attempts followed by successful privileged actions.
- Track outbound connections from Fusion Middleware hosts that follow interaction with the vulnerable component.
How to Mitigate CVE-2026-60370
Immediate Actions Required
- Apply the fixes provided in the Oracle Security Alert July 2026 to all affected 12.2.1.4.0 and 14.1.2.0.0 deployments.
- Inventory all Oracle Fusion Middleware instances that embed Oracle Platform Security for Java and confirm patch status.
- Restrict network access to OPSS and Fusion Middleware administrative HTTP interfaces to trusted management networks only.
- Review and reduce accounts holding low-level privileges on affected middleware.
Patch Information
Oracle released fixes for CVE-2026-60370 as part of the July 2026 Critical Patch Update cycle. Administrators should install the OPSS updates covering versions 12.2.1.4.0 and 14.1.2.0.0 as documented in the Oracle Security Alert July 2026. Oracle recommends applying Critical Patch Updates without delay because unpatched Fusion Middleware components are routinely targeted after advisories are published.
Workarounds
- Limit HTTP access to OPSS endpoints using network segmentation, reverse proxies, or web application firewall rules until patches are applied.
- Rotate credentials and keys stored in OPSS credential and keystore services after patching, especially if the environment logs indicate suspicious access.
- Enforce least privilege on all Fusion Middleware accounts, removing any low-privilege access that is not required for operations.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

