Description
Vulnerability in Oracle APEX (component: General). Supported versions that are affected are 24.1, 24.2 and 26.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle APEX. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle APEX accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-07-21
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an unauthenticated attacker with network access via HTTP to read a subset of data exposed through Oracle APEX. The flaw resides in the General component and results in unauthorized disclosure of sensitive information. The weakness can be classified as a confidentiality issue, where an attacker may obtain information they are not authorized to access.

Affected Systems

The affected product is Oracle APEX, versions 24.1, 24.2, and 26.1. These versions are listed as vulnerable in the official Oracle CPU July 2026 advisory. No other Oracle products are indicated as affected.

Risk and Exploitability

The CVSS v3.1 base score is 5.3, indicating a moderate risk primarily impacting confidentiality. The EPSS score is less than 1 percent, showing a low but nonzero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred as a network-based attack over standard HTTP, with no authentication required, enabling remote attackers to trigger the issue.

Generated by OpenCVE AI on August 4, 2026 at 04:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the APEX security patch released in the Oracle CPU July 2026 advisory
  • Restrict HTTP access to APEX by employing firewall rules or ACLs to limit exposure to trusted networks
  • Enable application logging and monitor for anomalous read activity that may indicate exploitation

Generated by OpenCVE AI on August 4, 2026 at 04:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Disclosure via Oracle APEX General Component

Tue, 28 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Disclosure of Oracle APEX Data via General Component

Fri, 24 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Disclosure of Oracle APEX Data via General Component

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle APEX (component: General). Supported versions that are affected are 24.1, 24.2 and 26.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle APEX. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle APEX accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle apex
CPEs cpe:2.3:a:oracle:apex:24.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:apex:24.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:apex:26.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle apex
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:17:05.118Z

Reserved: 2026-07-08T15:51:40.515Z

Link: CVE-2026-60156

cve-icon Vulnrichment

Updated: 2026-07-23T15:16:58.319Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:00:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor