CVE-2026-83011
largeUnauthenticated Takeover Flaw in Oracle Platform Security for Java (Fusion Middleware)
CVE-2026-83011 is a difficult-to-exploit, unauthenticated vulnerability in the Centralized Thirdparty Jars component of Oracle Platform Security for Java (OPSS), part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. An unauthenticated attacker with network access via HTTP who is able to overcome the high attack complexity could compromise OPSS, and successful attacks can result in a complete takeover of the product with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.1). Organizations running affected Fusion Middleware deployments (typically WebLogic-based environments where OPSS is bundled) are exposed wherever the relevant services are reachable over HTTP. Because exploitation is rated difficult, no public proof-of-concept exists, and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, real-world risk is currently lower than the score alone suggests. Defenders should nonetheless treat internet-reachable instances as priority patch candidates.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83011 to affected Fusion Middleware 12.2.1.4.0 and 14.1.2.0.0 deployments as soon as it is available for your release line. Restrict HTTP network access to WebLogic/OPSS admin and managed servers so they are reachable only from trusted networks, and verify that no affected instances are internet-facing. Review logs for unauthenticated anomalous HTTP requests against OPSS endpoints as an indicator of attempted exploitation.
| Oracle Platform Security for Java (Oracle Fusion Middleware) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.