Description
Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Enterprise Scheduling System). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of this vulnerability can result in takeover of Oracle SOA Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability resides in the Enterprise Scheduling System component of Oracle SOA Suite and allows an unauthenticated attacker to exploit the application over an HTTP network connection. The flaw is an improper authentication bypass, enabling the attacker to gain full control of the application, resulting in complete compromise of confidentiality, integrity, and availability of the targeted system.

Affected Systems

Oracle SOA Suite 12.2.1.4.0 and 14.1.2.0.0 from Oracle Corporation are affected. These versions are part of the Oracle Fusion Middleware suite.

Risk and Exploitability

According to the CVSS v3.1 score of 9.8, this is a critical vulnerability. The EPSS score of less than 1 percent indicates that exploitation is currently unlikely but could still occur, particularly if the SOA Suite instance is exposed to the Internet and the attacker has network access. The vulnerability is not yet listed in the CISA KEV catalog. Attackers do not require user interaction or privileges, making it easily exploitable via standard HTTP requests.

Generated by OpenCVE AI on August 2, 2026 at 21:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch published in the Oracle CPU July 2026 security advisory to fix the authentication bypass in the Enterprise Scheduling System.
  • If immediate patching is not feasible, restrict HTTP access to the SOA Suite server, limiting exposure to trusted administrators only.
  • Monitor application logs for anomalous HTTP requests and consider disabling or removing the Enterprise Scheduling System component until a fix is applied.

Generated by OpenCVE AI on August 2, 2026 at 21:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Authentication Bypass in Oracle SOA Suite Allowing Full System Compromise

Tue, 28 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Remote System Compromise in Oracle SOA Suite
Weaknesses CWE-287
CWE-306

Mon, 27 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Remote System Compromise in Oracle SOA Suite
Weaknesses CWE-287
CWE-306

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Enterprise Scheduling System). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of this vulnerability can result in takeover of Oracle SOA Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle soa Suite
CPEs cpe:2.3:a:oracle:soa_suite:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:soa_suite:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle soa Suite
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Soa Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T11:07:19.390Z

Reserved: 2026-07-08T15:51:40.543Z

Link: CVE-2026-60541

cve-icon Vulnrichment

Updated: 2026-07-27T11:07:03.290Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:00:07Z

Weaknesses