A vulnerability labeled as critical has been found in Oracle HTTP Server 12.2.1.4.0/14.1.2.0.0. The impacted element is an unknown function of the component Core. The manipulation results in improper authorization.

This vulnerability is reported as CVE-2026-34291. The attack can be launched remotely. No exploit exists.

The affected component should be upgraded.