External risk intelligence

Oracle Platform Security for Java Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60372

The vulnerability affects Oracle Fusion Middleware components and is explicitly accessible via HTTP without authentication. As a middleware platform often serving as the foundation for web applications, APIs, and edge services, it is commonly deployed in network-exposed configurations.

Missing Authentication

Oracle Platform Security For Java

12.2.1.4.014.1.2.0.0

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Platform Security for Java, a component of Oracle Fusion Middleware. This issue could allow an unauthenticated attacker to gain complete control of the affected system, potentially impacting confidentiality, integrity, and availability. The main concern is confirming relevance and exposure.

  • Unauthenticated attackers can take over Oracle Platform Security.
  • High impact vulnerability in a foundational middleware product.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending a specially crafted network request to the vulnerable Oracle Platform Security for Java component within Oracle Fusion Middleware. Because no authentication is required and the vulnerability is easily exploitable, a successful attack could lead to the complete takeover of the affected system.

  • Unauthenticated network access required.
  • Vulnerable component triggered via HTTP.
  • Complete system takeover possible.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker with network access to take over the Oracle Platform Security for Java. This means an attacker could gain complete control over the system.

  • Oracle Platform Security for Java system.
  • Network access via HTTP, no authentication needed.
  • Complete takeover of the Java security platform.

Operational Fix

Recommended remediation, mitigation, and detection steps

Oracle Fusion Middleware administrators are likely responsible for addressing this vulnerability, as it impacts Oracle Platform Security for Java. The immediate first step is to confirm the presence of the affected technology, assess its network exposure and business criticality, and identify the accountable system owner to plan remediation.

  • Application owners should own the issue.
  • Verify network reachability and business criticality.
  • Plan risk-based remediation with vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Platform Security for Java?

It is a foundational security component within Oracle Fusion Middleware, designed to manage identity, authorization, and cryptographic functions for Java-based applications. It acts as a bridge between the software and the underlying security infrastructure, ensuring that web services and enterprise applications are protected. Because it handles sensitive security tasks, it is deeply integrated into the middleware environment.

How does CVE-2026-60372 impact software security?

This vulnerability represents a critical weakness in the Centralized Thirdparty Jars component. It allows an attacker to bypass authentication entirely and gain unauthorized control over the system. This level of access compromises the integrity and confidentiality of the entire security platform, essentially granting the attacker the same permissions as the application itself.

Does any network request trigger this vulnerability?

No. While the vulnerability is accessible via HTTP, an attacker must send a specifically crafted request to interact with the vulnerable component. General traffic that does not contain the malicious payload will not trigger the security flaw. The primary precondition is simply that the attacker must have network reachability to the middleware service.

Is my system at risk if it is not internet-facing?

Halo Surface Signal indicates that because this middleware often serves as a foundation for APIs and web services, it is commonly exposed. If your instance is strictly internal, the risk is lower but not eliminated, as an attacker would first need access to your internal network. You should prioritize assets that have any form of network connectivity as per your organization's security posture.

What should I do first to address this CVE?

Begin by identifying all systems running Oracle Fusion Middleware versions 12.2.1.4.0 or 14.1.2.0.0. Once identified, determine which of these instances are reachable over the network. Coordinate with your application owners to confirm the business criticality of these systems and prepare for vendor-supplied patches, as these are necessary to remediate the underlying component flaw.

References