Description
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_http2.so). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HTTP Server executes to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in takeover of Oracle HTTP Server. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the mod_http2.so component of Oracle HTTP Server allows an attacker with local logon and low privileges to compromise the server. Successful exploitation can lead to full control over the Oracle HTTP Server instance, resulting in confidentiality, integrity, and availability impacts.

Affected Systems

Oracle Corporation’s Oracle HTTP Server version 14.1.2.0.0 is affected. The flaw resides in the mod_http2.so module used by this version of the software.

Risk and Exploitability

The CVSS score of 7.8 and the need for local, low‑privilege access indicate a substantial impact, although the attack surface is limited to the affected host. The EPSS score of less than 1% suggests exploitation is currently rare, and the vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 4, 2026 at 03:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU Jul 2026 patch that addresses the mod_http2.so vulnerability.
  • If the patch cannot be applied immediately, temporarily disable or unload the mod_http2.so module.
  • If disabling the module is not feasible, restrict local access to the Oracle HTTP Server until a patch is available.

Generated by OpenCVE AI on August 4, 2026 at 03:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Title Local privilege escalation allows Oracle HTTP Server takeover via mod_http2

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Local privilege escalation allows Oracle HTTP Server takeover via mod_http2

Mon, 27 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via mod_http2 in Oracle HTTP Server 14.1.2.0.0
Weaknesses CWE-863

Fri, 24 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via mod_http2 in Oracle HTTP Server 14.1.2.0.0
Weaknesses CWE-863

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_http2.so). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HTTP Server executes to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in takeover of Oracle HTTP Server. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle http Server
CPEs cpe:2.3:a:oracle:http_server:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle http Server
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Http Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-01T03:55:55.048Z

Reserved: 2026-07-08T15:51:40.543Z

Link: CVE-2026-60530

cve-icon Vulnrichment

Updated: 2026-07-24T18:11:23.515Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:45:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management