CVE-2026-60369
Oracle · Oracle Platform Security for Java
A critical vulnerability in Oracle Platform Security for Java allows low privileged attackers to compromise the environment via HTTP.
Executive summary
This critical vulnerability in Oracle Platform Security for Java allows low privileged attackers to escalate their access and achieve full system takeover.
Vulnerability
This flaw exists in the Centralized Thirdparty Jars component and allows an attacker with low privileges to execute arbitrary commands over HTTP, resulting in a complete takeover of the component and potentially impacting other integrated products.
Business impact
The CVSS score of 9.9 highlights an extreme risk of unauthorized access and system control. Even though the attacker requires low privileges, the potential for a scope change means that a successful attack could compromise the entire Oracle Fusion Middleware ecosystem, causing significant operational disruption and data loss.
Remediation
Immediate Action: Update to the latest version of Oracle Platform Security for Java as specified in the July 2026 Oracle Critical Patch Update.
Proactive Monitoring: Review access logs for suspicious activity originating from low-privileged service accounts and monitor for unexpected changes in system configuration.
Compensating Controls: Enforce the principle of least privilege for all accounts with access to the middleware environment and utilize WAF protections to inspect incoming traffic for exploitation patterns.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Organizations should prioritize applying the July 2026 CPU patches to all affected Oracle instances. While this vulnerability requires low-level privileges, the ability to escalate to a full takeover warrants immediate remediation to prevent internal threats or compromised accounts from expanding their access.