Summary
CVE-2026-70924 is a high-severity vulnerability affecting Oracle Web Services Manager, a component of Oracle Fusion Middleware. The flaw allows an unauthenticated attacker with network access via HTTPS to compromise the Web Services Security component, with successful exploitation potentially resulting in complete takeover of the affected system. Oracle rates this issue 8.1 (High) and describes it as "difficult to exploit."
Technical details
- Root cause: A flaw in the Web Services Security component of Oracle Web Services Manager that permits an attacker to compromise the product over the network.
- Trigger conditions: No authentication or user interaction is required; however, Oracle characterizes the vulnerability as having high attack complexity, meaning exploitation requires specific conditions or preparation that are outside the attacker’s direct control.
- Attack vector: Remote, over HTTPS (Network attack vector).
- Impact: Successful exploitation can compromise confidentiality, integrity, and availability of Oracle Web Services Manager, potentially resulting in complete takeover of the affected product.
Affected software
- Oracle Web Services Manager 12.2.1.4.0
- Oracle Web Services Manager 14.1.2.0.0
Severity
- CVSS v3.1 Base Score: 8.1 (High)
- Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the patches provided in Oracle’s associated Critical Patch Update / Security Alert (cspuaug2026) for Oracle Fusion Middleware. Upgrade Oracle Web Services Manager installations on the affected 12.2.1.4.0 and 14.1.2.0.0 release lines to the fixed versions specified in the Oracle advisory.
- If immediate patching is not possible: Restrict network access to Oracle Web Services Manager endpoints to trusted networks only, monitor HTTPS traffic to Fusion Middleware components for anomalous activity, and prioritize this issue for expedited patch deployment given the unauthenticated, network-exploitable nature of the flaw.
- Review Oracle’s official advisory for the complete list of affected sub-components and any prerequisite patch bundles required before applying the fix.

