Unauthenticated Access Flaw in Oracle REST Data Services by Oracle
CVE-2026-46830

5.3MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
28 May 2026

What is CVE-2026-46830?

A vulnerability exists in Oracle REST Data Services, specifically within the Mongoapi component, affecting versions 24.2.0 through 26.1.0. This flaw allows unauthenticated attackers with network access via HTTPS to exploit the service, potentially leading to unauthorized read access to certain accessible data. Due to its nature, the vulnerability poses a significant risk, making it crucial for users to implement necessary security measures to protect their data.

Affected Version(s)

Oracle REST Data Services 24.2.0 <= 26.1.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.