CVE-2026-60455

Oracle · Oracle Platform Security for Java

A critical vulnerability in the Centralized Thirdparty Jars component of Oracle Platform Security for Java allows low privileged attackers to achieve full system compromise.

Executive summary

An authenticated network-based vulnerability in Oracle Platform Security for Java poses a high risk of total system takeover.

Vulnerability

The vulnerability resides in the Centralized Thirdparty Jars component of Oracle Fusion Middleware. It enables an attacker with low privileges and network access to perform unauthorized actions, which may result in a full compromise of the affected installation.

Business impact

This vulnerability carries a CVSS score of 8.8, reflecting its potential for severe impact on confidentiality, integrity, and availability. Exploitation could allow an attacker to bypass security controls, leading to unauthorized data access or complete system disruption within the Oracle environment.

Remediation

Immediate Action: Install the security patches released by Oracle in the July 2026 Critical Patch Update.

Proactive Monitoring: Monitor application logs for signs of privilege escalation or unauthorized access attempts from low-privileged user accounts.

Compensating Controls: Utilize a Web Application Firewall to block suspicious traffic that deviates from standard operational behavior for the affected middleware.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high-severity rating, remediation should be treated as a priority. Administrators must ensure that all instances of Oracle Platform Security for Java are updated to the current secure version to mitigate the risk of exploitation.