Junglewise Threat Intelligence

CVE-2026-60156: Oracle APEX information disclosure in General component

CVE-2026-60156 · Severity: medium · CVSS 5.3 · Published 2026-07-21

Vendors: Oracle.

Executive brief

Oracle APEX, a low-code development platform used for building enterprise applications, contains a vulnerability that allows unauthorized individuals to access certain data. An attacker can exploit this over the internet without needing a username or password. While the attacker cannot modify or delete information, they can view a subset of sensitive data, potentially leading to information disclosure.

Technical details

A vulnerability in the 'General' component of Oracle APEX allows for unauthorized data retrieval. The flaw is classified as easily exploitable and can be triggered by an unauthenticated attacker with network access via HTTP. The vulnerability does not require user interaction or elevated privileges (PR:N/UI:N). Successful exploitation results in a loss of confidentiality, allowing the attacker to read a subset of Oracle APEX accessible data, though it does not provide integrity or availability impacts. Affected versions include 24.1, 24.2, and 26.1.

Affected products

  • Oracle APEX 24.1, 24.2, 26.1

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle Critical Patch Update July 2026

References