Description
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Apache Plugin). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in takeover of Oracle HTTP Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability resides in the Apache Plugin component of Oracle HTTP Server. An unauthenticated attacker with network access can exploit the identified flaw via an HTTP request. The flaw ultimately allows the attacker to take full control of the server, causing a complete compromise of confidentiality, integrity, and availability. The CVSS 3.1 base score of 9.8 reflects this high‑risk outcome.

Affected Systems

The affected systems are Oracle's Oracle HTTP Server, versions 12.2.1.4.0 and 14.1.2.0.0. These versions are distributed as part of Oracle Fusion Middleware. No other product versions have been confirmed to be vulnerable.

Risk and Exploitability

Attackers can reach the vulnerability over any network that exposes the HTTP service. The vector is network, access required is none, and the attack can be performed remotely without authentication. The EPSS score of less than 1% suggests that exploit activity has not been observed at scale, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the combination of a CVSS score of 9.8 and the ability to fully compromise the server means that the risk remains significant if the vulnerability is not addressed promptly.

Generated by OpenCVE AI on August 4, 2026 at 04:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle HTTP Server patch that addresses CVE-2026-60363.
  • Disable or remove the vulnerable Apache Plugin from the server if it is not required for application functionality.
  • Restrict direct network access to the HTTP server by limiting the IP ranges that can reach the service, or place the server behind a firewall and implement IP whitelisting or VPN.
  • Monitor HTTP traffic for suspicious requests and configure a web application firewall with rules targeting the specific vulnerability signature.

Generated by OpenCVE AI on August 4, 2026 at 04:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Server Takeover via Oracle HTTP Server Apache Plugin

Thu, 30 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Server Takeover via Oracle HTTP Server Apache Plugin

Tue, 28 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution in Oracle HTTP Server via Unauthenticated Plugin
Weaknesses CWE-78

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution in Oracle HTTP Server via Unauthenticated Plugin
Weaknesses CWE-284
CWE-78

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Apache Plugin). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in takeover of Oracle HTTP Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle http Server
CPEs cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:http_server:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle http Server
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Http Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-01T03:55:46.279Z

Reserved: 2026-07-08T15:51:40.532Z

Link: CVE-2026-60363

cve-icon Vulnrichment

Updated: 2026-07-24T17:05:41.481Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:15:03Z

Weaknesses