Vulnerability in Oracle HTTP Server of Oracle Fusion Middleware
CVE-2026-60530

7.8HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60530?

This vulnerability exists in the Oracle HTTP Server component of Oracle Fusion Middleware (mod_http2.so). It allows an attacker with low privileges, who has access to the infrastructure hosting the server, to exploit the issue and potentially take control of the Oracle HTTP Server. This security breach poses significant risks, affecting the confidentiality, integrity, and availability of the service, necessitating immediate attention and mitigation strategies by affected users.

Affected Version(s)

Oracle HTTP Server 14.1.2.0.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.