Vulnerability in Oracle HTTP Server of Oracle Fusion Middleware
CVE-2026-60431

8.6HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60431?

A vulnerability exists in the Oracle HTTP Server component of Oracle Fusion Middleware, specifically in the mod_proxy module. This issue permits an unauthenticated attacker with network access via HTTP to exploit the server. The vulnerability affects supported versions 12.2.1.4.0 and 14.1.2.0.0, potentially leading to unauthorized access to sensitive data. Attackers leveraging this flaw could compromise all data accessible through the Oracle HTTP Server, posing significant risks to security and data integrity.

Affected Version(s)

Oracle HTTP Server 12.2.1.4.0

Oracle HTTP Server 14.1.2.0.0

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.