Unauthorized Code Execution in Oracle Cloud Native Environment Command Line Interface
CVE-2026-35255

6.6MEDIUM

What is CVE-2026-35255?

This vulnerability allows unauthenticated attackers to exploit the Oracle Cloud Native Environment Command Line Interface by injecting malicious environment variables. If successful, attackers can execute arbitrary code, potentially compromising the integrity and security of the affected systems. Oracle has advised users to review their configurations and apply necessary updates to mitigate the risks associated with this vulnerability.

Affected Version(s)

Oracle Cloud Native Environment Command Line Interface v2.3.2

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.