Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-46775: Oracle REST Data Services Core Compromise via Network Attack

CVE-2026-46775
Summary

Oracle REST Data Services versions 24.2.0-26.1.0 are at risk of being taken over by an attacker with network access. This could impact other products as well. We recommend upgrading to a fixed version to prevent this risk.

Original title
Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network a...
Original description
Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle REST Data Services. While the vulnerability is in Oracle REST Data Services, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle REST Data Services. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
nvd CVSS3.1 9.9
Vulnerability type
CWE-284 Improper Access Control
Published: 28 May 2026 · Updated: 31 May 2026 · First seen: 28 May 2026