CVE-2026-82996
largeLocal Privilege Escalation to Full Takeover in Oracle Platform Security for Java
CVE-2026-82996 is a vulnerability in the Centralized Thirdparty Jars component of Oracle Platform Security for Java (OPSS), part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. It is easily exploitable by a low-privileged attacker who already has logon access to the host or infrastructure where OPSS executes — the attack vector is local, not network-facing. A successful exploit allows the attacker to escalate privileges and take over OPSS entirely, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.8). Because OPSS underpins security policy enforcement across WebLogic and Fusion Middleware deployments, a takeover could compromise the security posture of applications hosted on the same infrastructure. No public proof of concept is known, the flaw is not on the CISA KEV list, and there is no evidence of in-the-wild exploitation.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-82996 to all OPSS 12.2.1.4.0 and 14.1.2.0.0 installations, prioritizing hosts where multiple users or applications have local logon. Restrict interactive and service accounts on middleware hosts to the minimum OS privileges needed, since exploitation requires local low-privilege access. Review local account activity and privilege changes on Fusion Middleware servers for signs of escalation.
| Oracle Platform Security for Java (Oracle Fusion Middleware) | 12.2.1.4.0 |
| Oracle Platform Security for Java (Oracle Fusion Middleware) | 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Platform Security for Java executes to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.