Executive brief
A vulnerability in the Oracle HTTP Server, a component of Oracle Fusion Middleware, could allow a user with low-level access to the underlying server infrastructure to take full control of the web server. This could lead to the unauthorized access of sensitive data, modification of web content, or disruption of web services. The issue affects organizations using specific versions of Oracle Fusion Middleware in their web infrastructure.
Technical details
A vulnerability exists in the Core component of Oracle HTTP Server (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is categorized as easily exploitable and requires the attacker to have local logon credentials to the infrastructure where the server is executing. Successful exploitation allows a low-privileged user to achieve a complete takeover of the Oracle HTTP Server process, impacting confidentiality, integrity, and availability. The vulnerability is tracked under CVSS 3.1 with a base score of 7.8, emphasizing local access as the primary attack vector.
Affected products
- Oracle HTTP Server 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed: Initial publication of the CVE record.
- 2026-07-21: advisory: Oracle released the July 2026 Critical Patch Update.