Summary
CVE-2026-60737 is a critical, easily exploitable vulnerability in the Web Services Security component of Oracle Web Services Manager (OWSM), part of Oracle Fusion Middleware. The flaw allows an unauthenticated attacker with network access via HTTP to compromise the product, resulting in unauthorized creation, deletion, or modification of critical data and complete access to all data accessible to OWSM. It carries a CVSS v3.1 base score of 9.1 (Critical) and was published by Oracle on August 18, 2026.
Technical details
- Root cause: A weakness in the Web Services Security component of Oracle Web Services Manager that fails to properly enforce access controls, per Oracle’s advisory description.
- Trigger conditions: No authentication or user interaction is required; the attacker only needs network access to the vulnerable HTTP interface exposed by the affected OWSM deployment.
- Attack vector: Network (AV:N), low attack complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N).
- Impact: High confidentiality and high integrity impact — successful exploitation can result in unauthorized creation, deletion, or modification of critical data as well as complete unauthorized access to all data OWSM can reach. Availability impact is rated none (A:N), and the scope is unchanged (S:U).
Affected software
- Oracle Web Services Manager version 12.2.1.4.0
- Oracle Web Services Manager version 14.1.2.0.0
- (Component: Web Services Security, delivered as part of Oracle Fusion Middleware Infrastructure deployments)
Severity
- CVSS v3.1 Base Score: 9.1 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Mitigation and recommended actions
- Immediate: Apply the Oracle patches for Oracle Web Services Manager referenced in Oracle’s August 2026 Critical Patch Update / Security Alert advisory for versions 12.2.1.4.0 and 14.1.2.0.0. Organizations should update to the fixed release identified for their specific installed version as documented in the Oracle advisory.
- If immediate patching is not possible: Restrict network access to OWSM HTTP endpoints (e.g., via firewall rules, network segmentation, or VPN-only access) so that only trusted, authenticated internal systems can reach the Web Services Security component until the patch is applied. Continuously monitor OWSM logs for anomalous unauthenticated requests targeting web services security endpoints.
- Given the unauthenticated, network-exploitable nature of this vulnerability and its high CVSS score, treat patching as a priority for all internet- or internally-exposed Oracle Fusion Middleware deployments running the affected OWSM versions.

