Junglewise Threat Intelligence

CVE-2026-60438: Oracle HTTP Server data compromise in mod_ssl

CVE-2026-60438 · Severity: critical · CVSS 9.1 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A critical vulnerability has been identified in Oracle HTTP Server, a web server component used within the Oracle Fusion Middleware suite. An attacker can exploit this flaw over the network without needing a username or password. Successful exploitation could allow an attacker to view, modify, or delete sensitive business data, potentially leading to a full compromise of the web server's information.

Technical details

A vulnerability exists in the mod_ssl component of Oracle HTTP Server (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is classified as easily exploitable, requiring no authentication or user interaction (AV:N/AC:L/PR:N/UI:N). An attacker can leverage this vulnerability via HTTP to gain unauthorized access to the server's data. The impact is high for both confidentiality and integrity, meaning an attacker can read, create, delete, or modify all data accessible to the Oracle HTTP Server. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle HTTP Server 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published

References