Junglewise Threat Intelligence

CVE-2026-60431: Oracle HTTP Server unauthorized data access in mod_proxy

CVE-2026-60431 · Severity: high · CVSS 8.6 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle HTTP Server, a web server component used within the Oracle Fusion Middleware suite to manage web traffic. An unauthenticated attacker can exploit this flaw over the network to gain unauthorized access to sensitive data managed by the server. Because this component often sits in front of other business applications, a successful attack could lead to a broader compromise of integrated corporate systems and data.

Technical details

A vulnerability in the mod_proxy component of Oracle HTTP Server (part of Oracle Fusion Middleware) allows an unauthenticated remote attacker to compromise the server via HTTP. The flaw is classified as easily exploitable and results in a scope change (S:C), meaning an exploit can impact components beyond the HTTP server itself. Successful exploitation enables unauthorized access to critical data or full access to all data accessible by the Oracle HTTP Server. The vulnerability affects supported versions 12.2.1.4.0 and 14.1.2.0.0. Users should refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle HTTP Server 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: advisory: Published by Oracle and NVD

References