Security Vulnerability in Oracle Zero Data Loss Recovery Appliance Software
CVE-2026-21977
3.1LOW
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 20 January 2026
What is CVE-2026-21977?
A vulnerability exists within the Oracle Zero Data Loss Recovery Appliance Software that could be exploited to gain unauthorized read access to sensitive data. An attacker with network access can manipulate the system, although this requires interaction from a separate human entity. This flaw affects versions 23.1.0 through 23.1.202509, posing a risk of data exposure under certain conditions.
Affected Version(s)
Oracle Zero Data Loss Recovery Appliance Software 23.1.0 <= 23.1.202509