CVE-2026-34291
8.7Oracle · HTTP Server
An unauthenticated, network-adjacent vulnerability in the Oracle HTTP Server core allows for unauthorized data access and manipulation with significant impact due to scope change.
Executive summary
A high-severity vulnerability in Oracle HTTP Server allows unauthenticated remote attackers to compromise critical data and system integrity through network-based exploitation.
Vulnerability
The vulnerability exists in the Core component of Oracle HTTP Server and can be triggered by an unauthenticated attacker via HTTP. It enables unauthorized creation, deletion, or modification of critical data, and carries a scope change that extends the potential impact beyond the server itself.
Business impact
The CVSS score of 8.7 reflects a high-severity threat to confidentiality and integrity. Successful exploitation could lead to unauthorized access to sensitive information or the total compromise of data managed by the server, potentially resulting in severe regulatory non-compliance, financial loss, or operational disruption. The scope change indicates that the impact is not limited to the HTTP server but may affect other integrated infrastructure components.
Remediation
Immediate Action: Review the official Oracle Security Alert for April 2026 to identify and apply the necessary patches for versions 12.2.1.4.0 and 14.1.2.0.0.
Proactive Monitoring: Monitor server access logs for unusual HTTP requests, specifically those originating from unauthorized sources or attempting to access sensitive directories or configuration files.
Compensating Controls: Deploy a Web Application Firewall (WAF) with updated rulesets to detect and block malicious HTTP traffic patterns targeting the Oracle HTTP Server core.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical nature of the affected component and the potential for total data compromise, organizations should prioritize the identification of all instances of the vulnerable Oracle HTTP Server versions within their environment. Administrators must move quickly to apply the vendor-supplied patches once available, as the potential for unauthorized data manipulation poses a significant risk to organizational integrity.
More Oracle CVEs
Sources
- Oracle Advisory Vendor advisory