Vulnerability in Oracle REST Data Services Allows Unauthorized Access
CVE-2026-46839

9.9CRITICAL

Key Information:

Vendor

Oracle

Vendor
CVE Published:
28 May 2026

What is CVE-2026-46839?

A vulnerability exists in Oracle REST Data Services that allows an attacker with low privileges and network access via HTTPS to compromise the service. This flaw, present in supported versions from 24.2.0 to 26.1.0, could lead to a takeover of the service, impacting additional interconnected products. Attackers can exploit this vulnerability with relative ease, highlighting the need for immediate security measures to secure Oracle REST Data Services.

Affected Version(s)

Oracle REST Data Services 24.2.0 <= 26.1.0

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.