ZeroHour

CVE-2026-83020

large

Unauthenticated Takeover Flaw in Oracle Platform Security for Java (Fusion Middleware)

CVSS 3.1
10.0 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-83020 is a critical (CVSS 3.1 base score 10.0) vulnerability in the Centralized Thirdparty Jars component of Oracle Platform Security for Java (OPSS), part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges and no user interaction. Successful exploitation results in complete takeover of Oracle Platform Security for Java, and because of a scope change, attacks may significantly impact additional products beyond OPSS itself, with full impact to confidentiality, integrity, and availability. Organizations running WebLogic Server or other Fusion Middleware deployments on the affected OPSS versions are exposed wherever the relevant HTTP endpoints are reachable. As of now, the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known.

What to do: Apply the Oracle Critical Patch Update (CPU) that remediates CVE-2026-83020 to all OPSS installations on 12.2.1.4.0 and 14.1.2.0.0, prioritizing any systems with HTTP endpoints exposed to untrusted networks. Restrict network access to administrative and OPSS-related HTTP endpoints so only trusted hosts can reach them, and monitor logs for unauthenticated HTTP requests targeting Fusion Middleware/OPSS paths until patching is complete.

Affected
Oracle Platform Security for Java (Oracle Fusion Middleware, component: Centralized Thirdparty Jars)12.2.1.4.0, 14.1.2.0.0
Estimated exposure
large≈ tens of thousands of internet-exposed Oracle Fusion Middleware/WebLogic hosts, plus a larger unknown number of internal enterprise deployments — OPSS ships inside every Oracle WebLogic/Fusion Middleware domain, and public internet scan data has historically shown on the order of tens of thousands of internet-reachable WebLogic instances, many still on the long-supported 12.2.1.4.0…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java. While the vulnerability is in Oracle Platform Security for Java, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.