ZeroHour

CVE-2026-82995

large

Unauthenticated SOAP Flaw Enables Full Takeover of Oracle Platform Security for Java

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-82995 is a critical (CVSS 9.8) vulnerability in the Centralized Thirdparty Jars component of Oracle Platform Security for Java, part of Oracle Fusion Middleware. It is easily exploitable by an unauthenticated attacker with network access who sends crafted SOAP requests to a vulnerable instance, requiring no privileges and no user interaction. A successful attack can result in a complete takeover of Oracle Platform Security for Java, with high impact on confidentiality, integrity, and availability. Affected deployments are those running supported versions 12.2.1.4.0 and 14.1.2.0.0 of the product. The flaw is not currently listed in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, though the unauthenticated, network-reachable nature makes it attractive to attackers once details circulate.

What to do: Apply the Oracle Critical Patch Update that remediated CVE-2026-82995 to all Oracle Fusion Middleware installations running 12.2.1.4.0 or 14.1.2.0.0. Until patched, restrict network access to SOAP endpoints (block or authenticate at the perimeter/WAF so they are not reachable by unauthenticated clients), and verify WebLogic/OPSM ports are not exposed to the internet. Review logs for unexpected unauthenticated SOAP requests or suspicious administrative changes to Oracle Platform Security for Java policy stores.

Affected
Oracle Platform Security for Java (Oracle Fusion Middleware, component: Centralized Thirdparty Jars)12.2.1.4.0
Oracle Platform Security for Java (Oracle Fusion Middleware, component: Centralized Thirdparty Jars)14.1.2.0.0
Estimated exposure
largelikely tens of thousands of internet-exposed Oracle WebLogic/Fusion Middleware hosts (roughly 10,000–50,000), plus a larger internal-only enterprise population — Public internet scans (e.g., Shodan/Censys) routinely show tens of thousands of exposed Oracle WebLogic/Fusion Middleware SOAP and HTTP endpoints, and versions 12.2.1.4.x and 14.1.2.x are common long-supported releases in enterprise data…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.