Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-60366: Oracle Fusion Middleware: Unauthorized Access to Java Security

CVE-2026-60366
Summary

A critical vulnerability in Oracle Fusion Middleware's Java security system could allow hackers to access and control the system without a password. This could impact not only the Java security system but also other connected systems, potentially leading to unauthorized access and data theft. Update your Oracle Fusion Middleware to the latest version to protect your system.

Original title
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2...
Original description
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java. While the vulnerability is in Oracle Platform Security for Java, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
nvd CVSS3.1 10.0
Published: 22 Jul 2026 · Updated: 22 Jul 2026 · First seen: 22 Jul 2026