CVE-2026-82995
largeUnauthenticated SOAP Flaw Enables Full Takeover of Oracle Platform Security for Java
CVE-2026-82995 is a critical (CVSS 9.8) vulnerability in the Centralized Thirdparty Jars component of Oracle Platform Security for Java, part of Oracle Fusion Middleware. It is easily exploitable by an unauthenticated attacker with network access who sends crafted SOAP requests to a vulnerable instance, requiring no privileges and no user interaction. A successful attack can result in a complete takeover of Oracle Platform Security for Java, with high impact on confidentiality, integrity, and availability. Affected deployments are those running supported versions 12.2.1.4.0 and 14.1.2.0.0 of the product. The flaw is not currently listed in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, though the unauthenticated, network-reachable nature makes it attractive to attackers once details circulate.
What to do: Apply the Oracle Critical Patch Update that remediated CVE-2026-82995 to all Oracle Fusion Middleware installations running 12.2.1.4.0 or 14.1.2.0.0. Until patched, restrict network access to SOAP endpoints (block or authenticate at the perimeter/WAF so they are not reachable by unauthenticated clients), and verify WebLogic/OPSM ports are not exposed to the internet. Review logs for unexpected unauthenticated SOAP requests or suspicious administrative changes to Oracle Platform Security for Java policy stores.
| Oracle Platform Security for Java (Oracle Fusion Middleware, component: Centralized Thirdparty Jars) | 12.2.1.4.0 |
| Oracle Platform Security for Java (Oracle Fusion Middleware, component: Centralized Thirdparty Jars) | 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.