Junglewise Threat Intelligence

CVE-2026-60630: Oracle APEX information disclosure in Installation component

CVE-2026-60630 · Severity: medium · CVSS 5.5 · Published 2026-07-21

Vendors: Oracle.

Executive brief

Oracle APEX, a low-code development platform used for building enterprise applications, contains a security vulnerability in its installation component. An attacker who already has basic access to the underlying server infrastructure can exploit this flaw to gain unauthorized access to sensitive business data. This could lead to a significant breach of confidentiality for all data managed within the APEX environment.

Technical details

This vulnerability exists in the Installation component of Oracle APEX. It is classified as an information disclosure flaw that is easily exploitable by an attacker with local logon privileges to the infrastructure where Oracle APEX is running. The attack vector is local (AV:L), requiring the attacker to have a foothold on the underlying operating system or environment. Successful exploitation allows a low-privileged user to bypass intended access controls and gain unauthorized access to critical data or complete access to all data accessible by the Oracle APEX instance. The vulnerability has been addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle APEX 24.1, 24.2, 26.1

Timeline

  • 2026-07-21: advisory: Published as part of Oracle Critical Patch Update

References