CVE-2026-83020
largeUnauthenticated Takeover Flaw in Oracle Platform Security for Java (Fusion Middleware)
CVE-2026-83020 is a critical (CVSS 3.1 base score 10.0) vulnerability in the Centralized Thirdparty Jars component of Oracle Platform Security for Java (OPSS), part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges and no user interaction. Successful exploitation results in complete takeover of Oracle Platform Security for Java, and because of a scope change, attacks may significantly impact additional products beyond OPSS itself, with full impact to confidentiality, integrity, and availability. Organizations running WebLogic Server or other Fusion Middleware deployments on the affected OPSS versions are exposed wherever the relevant HTTP endpoints are reachable. As of now, the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known.
What to do: Apply the Oracle Critical Patch Update (CPU) that remediates CVE-2026-83020 to all OPSS installations on 12.2.1.4.0 and 14.1.2.0.0, prioritizing any systems with HTTP endpoints exposed to untrusted networks. Restrict network access to administrative and OPSS-related HTTP endpoints so only trusted hosts can reach them, and monitor logs for unauthenticated HTTP requests targeting Fusion Middleware/OPSS paths until patching is complete.
| Oracle Platform Security for Java (Oracle Fusion Middleware, component: Centralized Thirdparty Jars) | 12.2.1.4.0, 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java. While the vulnerability is in Oracle Platform Security for Java, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.