Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-60538: Oracle SOA Suite: Unauthenticated Takeover via HTTP
CVE-2026-60538
Summary
An attacker can take control of Oracle SOA Suite by sending a malicious request over the internet. This affects Oracle SOA Suite versions 12.2.1.4.0 and 14.1.2.0.0. It's essential to update these versions to the latest patch to prevent unauthorized access.
Original title
Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Enterprise Scheduling System). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exp...
Original description
Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Enterprise Scheduling System). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of this vulnerability can result in takeover of Oracle SOA Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
nvd CVSS3.1
9.8
Vulnerability type
CWE-306
Missing Authentication for Critical Function
Published: 21 Jul 2026 · Updated: 24 Jul 2026 · First seen: 24 Jul 2026