Vulnerability in Oracle HTTP Server of Oracle Fusion Middleware
CVE-2026-60454

7.8HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60454?

A vulnerability exists in Oracle HTTP Server within the Oracle Fusion Middleware suite that could allow a low privileged attacker to compromise the server. By gaining access to the infrastructure where the server operates, an attacker could seize control of the Oracle HTTP Server, posing significant security threats to confidentiality, integrity, and availability. This flaw impacts supported versions 12.2.1.4.0 and 14.1.2.0.0, making it crucial for organizations using these versions to apply mitigation strategies promptly.

Affected Version(s)

Oracle HTTP Server 12.2.1.4.0

Oracle HTTP Server 14.1.2.0.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.