Description
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_proxy). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. While the vulnerability is in Oracle HTTP Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-07-21
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the mod_proxy component of Oracle HTTP Server, allowing an unauthenticated attacker to send HTTP requests that bypass normal access controls. The flaw is an access‑control weakness (CWE‑200), enabling the unauthorized disclosure of data served by the server. Successful exploitation can lead to unauthorized access to critical data or full visibility into all accessible data, as reflected by the CVSS 3.1 score of 8.6 and a high impact on confidentiality.

Affected Systems

Oracle HTTP Server versions 12.2.1.4.0 and 14.1.2.0.0, part of Oracle Fusion Middleware, are affected. Administrators should confirm the presence of the mod_proxy module and ensure these versions are not exposed to untrusted networks.

Risk and Exploitability

The EPSS score is below 1%, suggesting a low likelihood of exploitation at the present moment, yet the absence of authentication and the high CVSS score keep the risk high. The vulnerability is not listed in CISA's KEV catalog, but the scope change indicates other dependent products could also suffer. Likely attack vectors involve direct HTTP requests to the exposed server, bypassing authentication to manipulate proxy forwarding and extract confidential data.

Generated by OpenCVE AI on August 2, 2026 at 22:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or upgrade to a newer version that contains the fix for the mod_proxy vulnerability.
  • Restrict or disable the mod_proxy module if it is not required, or configure it to forward traffic only to trusted internal destinations.
  • Implement network segmentation or firewall rules that limit inbound HTTP traffic to the Oracle HTTP Server, and enable logging to detect anomalous proxy activity.

Generated by OpenCVE AI on August 2, 2026 at 22:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Exposure via mod_proxy in Oracle HTTP Server

Tue, 28 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Exploit in Oracle HTTP Server's mod_proxy Component
Weaknesses CWE-285

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Exploit in Oracle HTTP Server's mod_proxy Component
Weaknesses CWE-200
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_proxy). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. While the vulnerability is in Oracle HTTP Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle http Server
CPEs cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:http_server:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle http Server
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Http Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:33:10.581Z

Reserved: 2026-07-08T15:51:40.536Z

Link: CVE-2026-60431

cve-icon Vulnrichment

Updated: 2026-07-24T15:33:06.786Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:30:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor