Summary
CVE-2026-60431 is a high-severity information disclosure vulnerability in the mod_proxy component of Oracle HTTP Server, affecting versions 12.2.1.4.0 and 14.1.2.0.0. Published as part of Oracle’s July 21, 2026 Critical Patch Update (CPU), the flaw allows unauthenticated remote attackers to access highly sensitive data across adjacent Oracle Fusion Middleware components, with a CVSS v3.1 base score of 8.6 (HIGH).
Technical details
- Root cause: The vulnerability resides in Oracle HTTP Server’s mod_proxy component, which inadequately restricts how inbound HTTP requests are forwarded, enabling unauthorized access to resources beyond the server itself.
- Trigger conditions: No authentication, no user interaction, and no special configuration are required. Attack complexity is rated Low.
- Attack vector: Remotely exploitable over the network via HTTP. An unauthenticated attacker with network access to the server can trigger the vulnerability directly.
- Impact: Successful exploitation results in unauthorized read access to critical data. The Scope metric is Changed (S:C), meaning exploitation can affect Oracle Fusion Middleware components beyond the directly targeted Oracle HTTP Server instance. There is no integrity or availability impact.
Affected software
- Oracle HTTP Server 12.2.1.4.0
- Oracle HTTP Server 14.1.2.0.0
Severity
- CVSS v3.1 Base Score: 8.6 (HIGH)
- Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate action: Apply Oracle’s July 2026 Critical Patch Update (CPU), which contains the official fix for CVE-2026-60431 for both affected versions (12.2.1.4.0 and 14.1.2.0.0).
- If patching cannot be applied immediately: Restrict network access to Oracle HTTP Server instances from untrusted or public-facing networks at the perimeter firewall level to reduce exposure until the CPU patch can be deployed.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

