CVE-2026-82995: Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. in Oracle Corporation Oracle Platform Security for Java
CVE-2026-82995 is a critical vulnerability in Oracle Platform Security for Java, part of Oracle Fusion Middleware. It allows an unauthenticated attacker with network access via SOAP to compromise the platform, potentially leading to full takeover. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. It has a CVSS 3.1 base score of 9.8, indicating high impact on confidentiality, integrity, and availability. Oracle has released security patches addressing this and many other vulnerabilities in their September 2026 Critical Security Patch Update. Customers are strongly advised to apply these patches promptly to mitigate risk.
AI Analysis
Technical Summary
This vulnerability in Oracle Platform Security for Java (component: Centralized Thirdparty Jars) allows an unauthenticated network attacker to exploit a flaw via SOAP, resulting in complete takeover of the product. The CVSS 3.1 base score is 9.8, indicating critical severity with high impact on confidentiality, integrity, and availability. Affected versions explicitly include 12.2.1.4.0 and 14.1.2.0.0. Oracle's September 2026 Critical Security Patch Update provides patches for this vulnerability along with many others across Oracle products.
Potential Impact
Successful exploitation leads to full compromise of Oracle Platform Security for Java, allowing an attacker to gain control over the component. This impacts confidentiality, integrity, and availability of the affected system, potentially enabling unauthorized access and disruption of services.
Mitigation Recommendations
Oracle has released official patches for this vulnerability in the September 2026 Critical Security Patch Update. Customers are strongly advised to apply these patches promptly to mitigate the risk. Oracle recommends remaining on actively-supported versions and applying security patches without delay.
CVE-2026-82995: Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. in Oracle Corporation Oracle Platform Security for Java
Description
CVE-2026-82995 is a critical vulnerability in Oracle Platform Security for Java, part of Oracle Fusion Middleware. It allows an unauthenticated attacker with network access via SOAP to compromise the platform, potentially leading to full takeover. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. It has a CVSS 3.1 base score of 9.8, indicating high impact on confidentiality, integrity, and availability. Oracle has released security patches addressing this and many other vulnerabilities in their September 2026 Critical Security Patch Update. Customers are strongly advised to apply these patches promptly to mitigate risk.
CVSS v3.1
Score 9.8critical
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in Oracle Platform Security for Java (component: Centralized Thirdparty Jars) allows an unauthenticated network attacker to exploit a flaw via SOAP, resulting in complete takeover of the product. The CVSS 3.1 base score is 9.8, indicating critical severity with high impact on confidentiality, integrity, and availability. Affected versions explicitly include 12.2.1.4.0 and 14.1.2.0.0. Oracle's September 2026 Critical Security Patch Update provides patches for this vulnerability along with many others across Oracle products.
Potential Impact
Successful exploitation leads to full compromise of Oracle Platform Security for Java, allowing an attacker to gain control over the component. This impacts confidentiality, integrity, and availability of the affected system, potentially enabling unauthorized access and disruption of services.
Mitigation Recommendations
Oracle has released official patches for this vulnerability in the September 2026 Critical Security Patch Update. Customers are strongly advised to apply these patches promptly to mitigate the risk. Oracle recommends remaining on actively-supported versions and applying security patches without delay.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-hjr3-jwpq-x7cc
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-82995"]
- Database Specific Severity
- CRITICAL
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aaa07e455bf5e2cf5ea33f6
Added to database: 09/16/2026, 03:07:16 UTC
Last enriched: 09/16/2026, 04:46:29 UTC
Last updated: 09/16/2026, 06:01:23 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.