Vulnerability in Oracle Fusion Middleware's Oracle Platform Security for Java
CVE-2026-60367

9.8CRITICAL

Key Information:

Vendor

Oracle

Vendor
CVE Published:
22 July 2026

What is CVE-2026-60367?

A significant security flaw exists within Oracle Fusion Middleware's Oracle Platform Security for Java that allows unauthenticated attackers with network access via HTTP to compromise the platform. Attackers can exploit this vulnerability easily to take control of the Oracle Platform Security for Java, leading to critical consequences including confidentiality breaches, and integrity and availability impacts. It is crucial for users of the affected versions to apply the necessary security measures promptly.

Affected Version(s)

Oracle Platform Security for Java 12.2.1.4.0

Oracle Platform Security for Java 14.1.2.0.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.