Impact
This vulnerability allows an unauthenticated attacker with network access via HTTP to read a subset of data exposed through Oracle APEX. The flaw resides in the General component and results in unauthorized disclosure of sensitive information. The weakness can be classified as a confidentiality issue, where an attacker may obtain information they are not authorized to access.
Affected Systems
The affected product is Oracle APEX, versions 24.1, 24.2, and 26.1. These versions are listed as vulnerable in the official Oracle CPU July 2026 advisory. No other Oracle products are indicated as affected.
Risk and Exploitability
The CVSS v3.1 base score is 5.3, indicating a moderate risk primarily impacting confidentiality. The EPSS score is less than 1 percent, showing a low but nonzero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred as a network-based attack over standard HTTP, with no authentication required, enabling remote attackers to trigger the issue.
OpenCVE Enrichment