CVE-2026-60369

Oracle · Oracle Platform Security for Java

A critical vulnerability in Oracle Platform Security for Java allows low privileged attackers to compromise the environment via HTTP.

Executive summary

This critical vulnerability in Oracle Platform Security for Java allows low privileged attackers to escalate their access and achieve full system takeover.

Vulnerability

This flaw exists in the Centralized Thirdparty Jars component and allows an attacker with low privileges to execute arbitrary commands over HTTP, resulting in a complete takeover of the component and potentially impacting other integrated products.

Business impact

The CVSS score of 9.9 highlights an extreme risk of unauthorized access and system control. Even though the attacker requires low privileges, the potential for a scope change means that a successful attack could compromise the entire Oracle Fusion Middleware ecosystem, causing significant operational disruption and data loss.

Remediation

Immediate Action: Update to the latest version of Oracle Platform Security for Java as specified in the July 2026 Oracle Critical Patch Update.

Proactive Monitoring: Review access logs for suspicious activity originating from low-privileged service accounts and monitor for unexpected changes in system configuration.

Compensating Controls: Enforce the principle of least privilege for all accounts with access to the middleware environment and utilize WAF protections to inspect incoming traffic for exploitation patterns.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Organizations should prioritize applying the July 2026 CPU patches to all affected Oracle instances. While this vulnerability requires low-level privileges, the ability to escalate to a full takeover warrants immediate remediation to prevent internal threats or compromised accounts from expanding their access.