CVE-2026-34291

8.7

Oracle · HTTP Server

An unauthenticated, network-adjacent vulnerability in the Oracle HTTP Server core allows for unauthorized data access and manipulation with significant impact due to scope change.

Executive summary

A high-severity vulnerability in Oracle HTTP Server allows unauthenticated remote attackers to compromise critical data and system integrity through network-based exploitation.

Vulnerability

The vulnerability exists in the Core component of Oracle HTTP Server and can be triggered by an unauthenticated attacker via HTTP. It enables unauthorized creation, deletion, or modification of critical data, and carries a scope change that extends the potential impact beyond the server itself.

Business impact

The CVSS score of 8.7 reflects a high-severity threat to confidentiality and integrity. Successful exploitation could lead to unauthorized access to sensitive information or the total compromise of data managed by the server, potentially resulting in severe regulatory non-compliance, financial loss, or operational disruption. The scope change indicates that the impact is not limited to the HTTP server but may affect other integrated infrastructure components.

Remediation

Immediate Action: Review the official Oracle Security Alert for April 2026 to identify and apply the necessary patches for versions 12.2.1.4.0 and 14.1.2.0.0.

Proactive Monitoring: Monitor server access logs for unusual HTTP requests, specifically those originating from unauthorized sources or attempting to access sensitive directories or configuration files.

Compensating Controls: Deploy a Web Application Firewall (WAF) with updated rulesets to detect and block malicious HTTP traffic patterns targeting the Oracle HTTP Server core.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical nature of the affected component and the potential for total data compromise, organizations should prioritize the identification of all instances of the vulnerable Oracle HTTP Server versions within their environment. Administrators must move quickly to apply the vendor-supplied patches once available, as the potential for unauthorized data manipulation poses a significant risk to organizational integrity.

More Oracle CVEs

Sources