Vulnerability in Oracle Fusion Middleware's Dynamic Monitoring Service
CVE-2026-35232

5.4MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 April 2026

What is CVE-2026-35232?

A vulnerability exists in Oracle Fusion Middleware's Dynamic Monitoring Service that can be exploited by low-privileged attackers with network access via HTTP. Successful exploitation requires human interaction from another user, opening the door to unauthorized updates, inserts, or deletions of Oracle Fusion Middleware accessible data. Furthermore, attackers may gain unauthorized read access to sensitive data, significantly affecting the integrity and confidentiality of the system. This makes the vulnerability worthy of attention from cybersecurity professionals.

Affected Version(s)

Oracle Fusion Middleware 12.2.1.4.0

Oracle Fusion Middleware 14.1.2.0.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.