Denial of Service Vulnerability in Oracle REST Data Services
CVE-2026-46829

7.5HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
28 May 2026

What is CVE-2026-46829?

A security vulnerability in Oracle REST Data Services, specifically within the Mongoapi component, allows an unauthenticated attacker with network access via HTTPS to exploit the system. This could lead to a denial of service through hangs or crashes, rendering the service unavailable. Affected versions include 24.2.0 through 26.1.0, making it essential for users to review their security posture and apply available patches to mitigate the risks associated with this vulnerability.

Affected Version(s)

Oracle REST Data Services 24.2.0 <= 26.1.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.