Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cpujul2026.html |
|
Thu, 30 Jul 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local Access Vulnerability in Oracle APEX Installation Enables Unauthorized Data Access |
Tue, 28 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Oracle APEX Installation Vulnerability Enables Local Compromise and Data Exposure | |
| Weaknesses | CWE-200 |
Mon, 27 Jul 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Jul 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Oracle APEX Installation Vulnerability Enables Local Compromise and Data Exposure | |
| Weaknesses | CWE-200 CWE-284 |
Tue, 21 Jul 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in Oracle APEX (component: Installation). Supported versions that are affected are 24.1, 24.2 and 26.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle APEX executes to compromise Oracle APEX. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle APEX accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N). | |
| First Time appeared |
Oracle
Oracle apex |
|
| CPEs | cpe:2.3:a:oracle:apex:24.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:apex:24.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:apex:26.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Oracle
Oracle apex |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2026-07-27T12:38:50.822Z
Reserved: 2026-07-08T15:51:40.549Z
Link: CVE-2026-60630
Updated: 2026-07-27T12:38:47.403Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-30T13:45:03Z
-
CWE-284
Improper Access Control