Exploitable Vulnerability in Oracle REST Data Services Impacting Security
CVE-2026-46775

9.9CRITICAL

Key Information:

Vendor

Oracle

Vendor
CVE Published:
28 May 2026

What is CVE-2026-46775?

A vulnerability exists in Oracle REST Data Services affecting versions 24.2.0 through 26.1.0, which allows a low-privileged attacker with network access via HTTPS to compromise the integrity and confidentiality of the service. This flaw could lead to unauthorized control over the Oracle REST Data Services, making it crucial for organizations to implement the necessary patches and mitigate potential threats. The vulnerability's implications extend beyond the affected product, possibly influencing other related systems in the network.

Affected Version(s)

Oracle REST Data Services 24.2.0 <= 26.1.0

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.