Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-60455

CVE-2026-60455: Oracle Platform Security for Java RCE

CVE-2026-60455 is a remote code execution vulnerability in Oracle Platform Security for Java that enables complete system takeover. This post covers the technical details, affected versions, CVSS 8.8 severity, and mitigation.

Published:

CVE-2026-60455 Overview

CVE-2026-60455 affects Oracle Platform Security for Java, a component of Oracle Fusion Middleware. The vulnerability resides in the Centralized Thirdparty Jars component and impacts versions 12.2.1.4.0 and 14.1.2.0.0. A low-privileged attacker with network access via HTTP can exploit this issue to fully compromise the affected product. Oracle rates the flaw with a CVSS 3.1 Base Score of 8.8, reflecting high impact to confidentiality, integrity, and availability.

Critical Impact

Successful exploitation results in complete takeover of Oracle Platform Security for Java, granting attackers control over authenticated Fusion Middleware security services.

Affected Products

  • Oracle Platform Security for Java 12.2.1.4.0
  • Oracle Platform Security for Java 14.1.2.0.0
  • Oracle Fusion Middleware deployments using Centralized Thirdparty Jars

Discovery Timeline

Technical Details for CVE-2026-60455

Vulnerability Analysis

The flaw exists in the Centralized Thirdparty Jars component of Oracle Platform Security for Java (OPSS). OPSS provides authentication, authorization, credential mapping, and cryptography services to Fusion Middleware applications. A successful attack against this component compromises the entire security service, cascading risk to every application that depends on OPSS for identity and access enforcement.

Oracle categorizes the vulnerability as easily exploitable. An authenticated attacker holding only low-privileged credentials can send crafted HTTP requests to trigger the flaw. The scope remains unchanged, meaning the compromise is contained to OPSS itself, but the impact against that component is high across confidentiality, integrity, and availability.

Root Cause

Oracle has not disclosed technical root-cause details in the public advisory. The Centralized Thirdparty Jars component manages shared third-party libraries used by OPSS. Vulnerabilities in this class of component typically stem from unsafe deserialization, insecure library loading, or improper validation of inputs processed by bundled dependencies.

Attack Vector

Exploitation requires network access over HTTP and valid low-privileged credentials. No user interaction is needed. An attacker with basic authenticated access to a Fusion Middleware instance can send targeted requests to the vulnerable OPSS endpoint. Refer to the Oracle Security Alert July 2026 for vendor-supplied remediation guidance.

Detection Methods for CVE-2026-60455

Indicators of Compromise

  • Unexpected HTTP requests targeting OPSS endpoints from low-privileged accounts
  • Anomalous access to Centralized Thirdparty Jars component URIs within Fusion Middleware
  • New administrative or credential-mapping changes in OPSS that do not correlate with change tickets
  • Java process anomalies in WebLogic or Fusion Middleware hosting OPSS

Detection Strategies

  • Monitor Fusion Middleware and WebLogic access logs for HTTP requests from non-administrative users invoking OPSS-related paths
  • Alert on abnormal invocations of third-party JAR handlers or class-loading routines within OPSS
  • Baseline authentication and authorization traffic to identify deviations that indicate privilege escalation attempts

Monitoring Recommendations

  • Enable verbose audit logging for OPSS authentication, authorization, and credential store operations
  • Forward Fusion Middleware logs to a centralized SIEM for correlation with identity and network telemetry
  • Track process execution and outbound connections from Java processes hosting OPSS to detect post-exploitation activity

How to Mitigate CVE-2026-60455

Immediate Actions Required

  • Apply the July 2026 Oracle Critical Patch Update to all affected Fusion Middleware deployments
  • Inventory Oracle Platform Security for Java instances running versions 12.2.1.4.0 and 14.1.2.0.0
  • Restrict HTTP access to Fusion Middleware administrative and OPSS endpoints to trusted networks
  • Review and reduce accounts that hold low-privileged access to Fusion Middleware

Patch Information

Oracle released fixes as part of the July 2026 Critical Patch Update. Administrators must apply the patches referenced in the Oracle Security Alert July 2026 to versions 12.2.1.4.0 and 14.1.2.0.0. No official workaround replaces patching.

Workarounds

  • Place Fusion Middleware behind a reverse proxy or WAF that restricts access to OPSS endpoints
  • Enforce network segmentation so only trusted management networks reach Fusion Middleware HTTP interfaces
  • Rotate credentials for accounts with access to OPSS if compromise is suspected while patching is pending

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.