Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-60371

CVE-2026-60371: Oracle Platform Security Escalation Flaw

CVE-2026-60371 is a privilege escalation vulnerability in Oracle Platform Security for Java affecting versions 12.2.1.4.0 and 14.1.2.0.0. This critical flaw can lead to complete system takeover. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2026-60371 Overview

CVE-2026-60371 is a high-severity vulnerability in the Oracle Platform Security for Java (OPSS) product of Oracle Fusion Middleware. The flaw resides in the Centralized Thirdparty Jars component and affects versions 12.2.1.4.0 and 14.1.2.0.0. A low-privileged attacker with access to the physical communication segment attached to the hardware running OPSS can compromise the product. The vulnerability carries a scope change, meaning successful exploitation may impact additional products beyond OPSS itself. Successful attacks result in complete takeover of Oracle Platform Security for Java, affecting confidentiality, integrity, and availability.

Critical Impact

Successful exploitation results in full takeover of Oracle Platform Security for Java with potential to impact additional integrated Oracle Fusion Middleware products through scope change.

Affected Products

  • Oracle Platform Security for Java version 12.2.1.4.0
  • Oracle Platform Security for Java version 14.1.2.0.0
  • Oracle Fusion Middleware components consuming the Centralized Thirdparty Jars

Discovery Timeline

  • 2026-07-22 - CVE-2026-60371 published to NVD
  • 2026-07-22 - Last updated in NVD database
  • July 2026 - Included in Oracle Critical Patch Update advisory

Technical Details for CVE-2026-60371

Vulnerability Analysis

CVE-2026-60371 affects the Centralized Thirdparty Jars component of Oracle Platform Security for Java. OPSS provides the underlying security framework for Oracle Fusion Middleware, including authentication, authorization, credential management, and cryptographic services. A compromise of this layer undermines security guarantees across every product consuming it.

The vulnerability requires adjacent network access, meaning the attacker must be on the same physical or logical network segment as the target host. Exploitation is rated difficult and requires low-level authenticated privileges. Despite the elevated exploitation barriers, successful attacks yield full compromise of OPSS.

The scope change indicator signals that the security impact extends beyond OPSS itself. Downstream Oracle Fusion Middleware products that trust OPSS for security functions may be affected once the framework is subverted.

Root Cause

Oracle has not published the specific weakness class for this issue. Based on the affected component — Centralized Thirdparty Jars — the root cause involves the handling or trust boundaries of shared third-party library dependencies used across Fusion Middleware. Refer to the Oracle advisory for authoritative technical detail.

Attack Vector

The attack vector is Adjacent Network. The attacker must have access to the physical communication segment attached to the hardware where OPSS executes. The attacker also requires low-privilege authentication on the target environment. User interaction is not required.

See the Oracle Security Alert July 2026 for exploitation prerequisites and vendor-supplied technical guidance.

Detection Methods for CVE-2026-60371

Indicators of Compromise

  • Unexpected modifications to files under the OPSS Centralized Thirdparty Jars directory
  • New or unauthorized authentication events involving OPSS-managed credentials
  • Anomalous outbound connections from Fusion Middleware hosts to adjacent network peers
  • Unexpected JVM restarts or configuration reloads on WebLogic domains hosting OPSS

Detection Strategies

  • Enforce integrity monitoring on OPSS installation directories and third-party jar repositories
  • Correlate adjacent-network authentication attempts with OPSS service events
  • Baseline normal WebLogic and Fusion Middleware process behavior and alert on deviations
  • Review Oracle audit logs for privilege escalation and configuration changes tied to OPSS

Monitoring Recommendations

  • Ingest Fusion Middleware and WebLogic logs into a centralized SIEM with retention aligned to incident response requirements
  • Monitor east-west traffic on the network segment hosting OPSS servers for lateral movement patterns
  • Alert on modifications to OPSS policy stores, credential stores, and keystore files
  • Track privileged account usage on Fusion Middleware hosts continuously

How to Mitigate CVE-2026-60371

Immediate Actions Required

  • Apply the July 2026 Oracle Critical Patch Update to affected OPSS versions 12.2.1.4.0 and 14.1.2.0.0
  • Restrict network access to Fusion Middleware hosts using segmentation and firewall policies
  • Audit and reduce local privileges on hosts running OPSS
  • Rotate credentials and keys managed by OPSS after patching to invalidate any pre-patch compromise

Patch Information

Oracle addressed CVE-2026-60371 in the July 2026 Critical Patch Update. Consult the Oracle Security Alert July 2026 for patch identifiers, applicability, and installation prerequisites specific to your Fusion Middleware deployment.

Workarounds

  • Isolate OPSS hosts on a dedicated network segment with strict ingress and egress controls
  • Enforce strong authentication and least-privilege access for accounts on the OPSS network segment
  • Disable unused Fusion Middleware components that consume Centralized Thirdparty Jars where feasible
  • Increase logging verbosity for OPSS operations until patching is complete
bash
# Verify OPSS version on WebLogic domain
cd $ORACLE_HOME/oracle_common/modules/oracle.jps
ls -la

# Review patched inventory after applying CPU July 2026
$ORACLE_HOME/OPatch/opatch lsinventory | grep -i jps

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.