Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-46839: Oracle REST Data Services (24.2.0-26.1.0) can be taken over via HTTPS

CVE-2026-46839
Summary

If an attacker with network access to your Oracle REST Data Services (via HTTPS) has low privileges, they may be able to take control of your entire Oracle REST Data Services system. This could impact other connected products as well. We recommend updating to a non-affected version of Oracle REST Data Services to prevent potential takeover.

Original title
Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network a...
Original description
Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle REST Data Services. While the vulnerability is in Oracle REST Data Services, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle REST Data Services. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
nvd CVSS3.1 9.9
Vulnerability type
CWE-284 Improper Access Control
Published: 28 May 2026 · Updated: 31 May 2026 · First seen: 28 May 2026