CVE-2026-60431: Infoleak
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: modproxy). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. While the vulnerability is in Oracle HTTP Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60431?
The severity of CVE-2026-60431 is rated as high with a score of 8.6.
How do I fix CVE-2026-60431?
To fix CVE-2026-60431, update to a patched version of Oracle HTTP Server that addresses the vulnerability.
What products are affected by CVE-2026-60431?
CVE-2026-60431 affects Oracle HTTP Server in the Oracle Fusion Middleware component for versions 12.2.1.4.0 and 14.1.2.0.0.
What type of attack does CVE-2026-60431 allow?
CVE-2026-60431 allows unauthenticated attackers with network access via HTTP to potentially compromise the Oracle HTTP Server.
What is the CVSS score breakdown for CVE-2026-60431?
CVE-2026-60431 has a CVSS score of 8.6, which includes access vector as network, access complexity as low, and confidentiality impact as high.