Description
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Platform Security for Java executes to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized local privilege escalation leading to complete takeover of Oracle Platform Security for Java
Action: Patch or restrict
AI Analysis

Impact

The vulnerability resides in the Centralized Thirdparty Jars component of Oracle Platform Security for Java. It is an improper authorization flaw (CWE‑284) that can be exploited by any low‑privileged user who has logged onto the infrastructure where the product is running. An attacker who succeeds can compromise the entire Platform Security for Java installation, resulting in full loss of confidentiality, integrity.

Affected Systems

Oracle Corporation’s Oracle Platform Security for Java is affected for versions 12.2.1.4.0 and 14.1.2.0.0 only.

Risk and Exploitability

The CVSS v3.1 score of 7.8 indicates a high impact with local access, low complexity, and low privileges required. The EPSS score of less than 1 % shows that exploitation is currently very unlikely but still possible. The lack of KEV listing means no confirmed widespread exploitation is known. The likely attack vector is a local attacker who can log into the host that runs the Platform Security for Java process and then exercises the compromised authorization control to take over the application.

Generated by OpenCVE AI on September 17, 2026 at 04:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security patch or upgrade to a newer Oracle Platform Security for Java version that addresses the privilege escalation flaw.
  • Limit local user accounts to the minimal privileges required for their duties and remove arbitrary logon rights to the system hosting the Platform Security component.
  • Enable comprehensive audit logging for the Platform Security for Java activity.
  • Conduct regular penetration tests focused on local privilege escalation to verify that the vulnerability has been remediated.

Generated by OpenCVE AI on September 17, 2026 at 04:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Allowing Full Takeover of Oracle Platform Security for Java

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Platform Security for Java executes to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle platform Security For Java
CPEs cpe:2.3:a:oracle:platform_security_for_java:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:platform_security_for_java:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle platform Security For Java
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Platform Security For Java
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:28:41.830Z

Reserved: 2026-08-31T15:40:57.328Z

Link: CVE-2026-82996

cve-icon Vulnrichment

Updated: 2026-09-16T14:54:31.826Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:06.127

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-82996

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T04:45:17Z

Weaknesses