CVE-2026-82994
moderateUnauthenticated LDAP-Reachable Takeover in Oracle Platform Security for Java
Oracle Platform Security for Java (OPSS), a component of Oracle Fusion Middleware, contains a critical flaw in its Centralized Thirdparty Jars component affecting versions 12.2.1.4.0 and 14.1.2.0.0. An unauthenticated remote attacker who can reach the product over LDAP can exploit the vulnerability with low complexity and no user interaction or privileges required. A successful attack results in a complete takeover of Oracle Platform Security for Java, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 9.8). Organizations running the affected Fusion Middleware releases, particularly those with LDAP listeners reachable from untrusted networks, are at risk. There is no evidence of in-the-wild exploitation and no public proof-of-concept is known, and the CVE is not on the CISA Known Exploited Vulnerabilities catalog.
What to do: Apply the Oracle Critical Patch Update that remediates this CVE to installations of Oracle Platform Security for Java 12.2.1.4.0 and 14.1.2.0.0 as soon as the fix is available. Until patched, restrict network access so LDAP listeners and Fusion Middleware administrative endpoints are not reachable from untrusted or internet-facing networks. Review LDAP and middleware logs for unauthenticated or anomalous bind/query activity against OPSS endpoints and monitor Oracle's advisories for updates.
| Oracle Platform Security for Java (Oracle Fusion Middleware, component: Centralized Thirdparty Jars) | 12.2.1.4.0, 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Weakness
- CWE-287, CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.