Description
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HTTP Server executes to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in takeover of Oracle HTTP Server. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle HTTP Server allows a local attacker who can log onto the underlying infrastructure to compromise and fully take control of the web server. The weakness grants an attacker the ability to alter data, execute commands, and disrupt services, resulting in high confidentiality, integrity, and availability impacts. This is a permission management flaw identified by CWE-269. The entry lists a CVSS 3.1 a substantial risk level once exploited.

Affected Systems

Oracle Corporation's Oracle HTTP Server, specifically versions 12.2.1.4.0 and 14.1.2.0.0. Upgrades to later releases are required to avoid exploitation.

Risk and Exploitability

The CVSS score indicates serious impact, but the EPSS value of less than 1% shows that the likelihood of automated exploitation is very low. Because the vector is local with low privilege, an attacker must already have access to the host where the server runs, as inferred from the description. The vulnerability is not yet listed in CISA's KEV catalog, suggesting no confirmed public exploitation, yet the potential for local compromise remains significant.

Generated by OpenCVE AI on August 4, 2026 at 03:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle HTTP Server patch released in the CPU Jul 2026 advisory.
  • Restrict local user privileges on the host that runs Oracle HTTP Server to prevent unauthorized access.
  • Disable or remove any unused web services or modules that could be leveraged by a local attacker.

Generated by OpenCVE AI on August 4, 2026 at 03:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle HTTP Server Enables Full Takeover

Tue, 28 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege Local Exploit Enables Full Oracle HTTP Server Compromise
Weaknesses CWE-285

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege Local Exploit Enables Full Oracle HTTP Server Compromise
Weaknesses CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HTTP Server executes to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in takeover of Oracle HTTP Server. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle http Server
CPEs cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:http_server:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle http Server
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Http Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-01T03:55:53.864Z

Reserved: 2026-07-08T15:51:40.537Z

Link: CVE-2026-60454

cve-icon Vulnrichment

Updated: 2026-07-24T14:22:20.414Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:00:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management