Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-60370

CVE-2026-60370: Oracle Platform Security Escalation Flaw

CVE-2026-60370 is a privilege escalation vulnerability in Oracle Platform Security for Java that allows attackers to gain unauthorized control. This article covers the technical details, affected versions, security impact, and mitigation.

Published:

CVE-2026-60370 Overview

CVE-2026-60370 is a high-severity vulnerability in Oracle Platform Security for Java, a component of Oracle Fusion Middleware. The flaw resides in the Centralized Thirdparty Jars component and affects supported versions 12.2.1.4.0 and 14.1.2.0.0. A low-privileged attacker with network access over HTTP can exploit the weakness to compromise the product. Successful exploitation results in full takeover of Oracle Platform Security for Java, impacting confidentiality, integrity, and availability.

Critical Impact

Successful attacks result in complete takeover of Oracle Platform Security for Java, exposing sensitive middleware credentials, policies, and identity artifacts.

Affected Products

  • Oracle Platform Security for Java 12.2.1.4.0
  • Oracle Platform Security for Java 14.1.2.0.0
  • Oracle Fusion Middleware deployments using the Centralized Thirdparty Jars component

Discovery Timeline

Technical Details for CVE-2026-60370

Vulnerability Analysis

Oracle Platform Security for Java (OPSS) provides authentication, authorization, credential storage, and cryptographic services for Oracle Fusion Middleware. The vulnerable Centralized Thirdparty Jars component manages shared third-party libraries used across middleware deployments. An authenticated attacker with low privileges can send crafted HTTP requests to the exposed interfaces to compromise the service. Exploitation is difficult and requires specific conditions to succeed, but the resulting compromise gives an attacker control over identity, credential, and policy operations handled by OPSS.

Root Cause

Oracle has not published detailed root-cause information. The advisory attributes the flaw to the Centralized Thirdparty Jars component within OPSS, which handles shared libraries consumed by middleware services. See the Oracle Security Alert July 2026 for vendor-supplied technical context.

Attack Vector

The attack vector is network-based over HTTP. The attacker must already hold low-level privileges within the environment and must overcome conditions that make exploitation difficult. No user interaction is required, and the scope remains unchanged. A successful attack yields high impact to confidentiality, integrity, and availability, effectively allowing full takeover of Oracle Platform Security for Java.

No public exploit code or proof of concept has been observed for this issue. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

Detection Methods for CVE-2026-60370

Indicators of Compromise

  • Unexpected authenticated HTTP requests targeting OPSS endpoints or Centralized Thirdparty Jars management interfaces.
  • Anomalous read or write activity against OPSS credential stores, policy stores, or keystore artifacts.
  • New or modified third-party JAR files in the centralized library location outside of maintenance windows.

Detection Strategies

  • Enable and review audit logs for Oracle Fusion Middleware and OPSS, focusing on privileged operations performed by low-privileged accounts.
  • Correlate WebLogic and OPSS access logs with identity provider logs to detect abnormal reuse of low-privilege accounts against OPSS interfaces.
  • Compare deployed third-party JAR hashes against a known-good baseline to identify unauthorized replacement or tampering.

Monitoring Recommendations

  • Alert on any modification to files under the OPSS domain and centralized JAR directories.
  • Monitor administrative HTTP endpoints of Fusion Middleware for repeated failed authorization attempts followed by successful privileged actions.
  • Track outbound connections from Fusion Middleware hosts that follow interaction with the vulnerable component.

How to Mitigate CVE-2026-60370

Immediate Actions Required

  • Apply the fixes provided in the Oracle Security Alert July 2026 to all affected 12.2.1.4.0 and 14.1.2.0.0 deployments.
  • Inventory all Oracle Fusion Middleware instances that embed Oracle Platform Security for Java and confirm patch status.
  • Restrict network access to OPSS and Fusion Middleware administrative HTTP interfaces to trusted management networks only.
  • Review and reduce accounts holding low-level privileges on affected middleware.

Patch Information

Oracle released fixes for CVE-2026-60370 as part of the July 2026 Critical Patch Update cycle. Administrators should install the OPSS updates covering versions 12.2.1.4.0 and 14.1.2.0.0 as documented in the Oracle Security Alert July 2026. Oracle recommends applying Critical Patch Updates without delay because unpatched Fusion Middleware components are routinely targeted after advisories are published.

Workarounds

  • Limit HTTP access to OPSS endpoints using network segmentation, reverse proxies, or web application firewall rules until patches are applied.
  • Rotate credentials and keys stored in OPSS credential and keystore services after patching, especially if the environment logs indicate suspicious access.
  • Enforce least privilege on all Fusion Middleware accounts, removing any low-privilege access that is not required for operations.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.