Unauthorized Code Execution in Oracle Cloud Native Environment Command Line Interface
CVE-2026-35255
6.6MEDIUM
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 6 May 2026
What is CVE-2026-35255?
This vulnerability allows unauthenticated attackers to exploit the Oracle Cloud Native Environment Command Line Interface by injecting malicious environment variables. If successful, attackers can execute arbitrary code, potentially compromising the integrity and security of the affected systems. Oracle has advised users to review their configurations and apply necessary updates to mitigate the risks associated with this vulnerability.
Affected Version(s)
Oracle Cloud Native Environment Command Line Interface v2.3.2