Executive brief
Oracle APEX, a low-code development platform used for building enterprise applications, contains a vulnerability that allows unauthorized individuals to access certain data. An attacker can exploit this over the internet without needing a username or password. While the attacker cannot modify or delete information, they can view a subset of sensitive data, potentially leading to information disclosure.
Technical details
A vulnerability in the 'General' component of Oracle APEX allows for unauthorized data retrieval. The flaw is classified as easily exploitable and can be triggered by an unauthenticated attacker with network access via HTTP. The vulnerability does not require user interaction or elevated privileges (PR:N/UI:N). Successful exploitation results in a loss of confidentiality, allowing the attacker to read a subset of Oracle APEX accessible data, though it does not provide integrity or availability impacts. Affected versions include 24.1, 24.2, and 26.1.
Affected products
- Oracle APEX 24.1, 24.2, 26.1
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle Critical Patch Update July 2026