Vulnerability in Oracle Fusion Middleware Affecting Oracle Security Service
CVE-2026-35252

6.4MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 April 2026

What is CVE-2026-35252?

A cybersecurity vulnerability exists in the Oracle Security Service component of Oracle Fusion Middleware that could allow attackers with low privileges and network access via HTTPS to manipulate the service. Exploitation of this vulnerability requires user interaction from a third party, potentially leading to unauthorized creation, deletion, or modification of critical data accessible through the service. The affected versions include Oracle Fusion Middleware 12.2.1.4.0 and 12.1.3.0.0, highlighting the need for immediate attention to mitigate risks of data breaches.

Affected Version(s)

Oracle Security Service 12.2.1.4.0

Oracle Security Service 12.1.3.0.0

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.