Junglewise Threat Intelligence

CVE-2026-35253: Oracle Macaron Tool host address validation failure

CVE-2026-35253 · Severity: medium · CVSS 4.7 · Published 2026-05-06

Vendors: Oracle.

Executive brief

Oracle Macaron Tool, an open-source security analysis utility, contains a vulnerability that can lead to improper host address validation. An unauthenticated attacker could exploit this flaw over the network to bypass certain security checks or redirect users to untrusted sites. This could potentially lead to unauthorized information disclosure or facilitate further phishing attacks against users of the tool.

Technical details

A vulnerability classified as an Origin Validation Error (CWE-346) and Open Redirect (CWE-601) exists in Oracle Macaron Tool v0.22.0. The flaw stems from improper validation of host addresses during HTTP requests. An unauthenticated remote attacker can exploit this by sending a crafted request, requiring minimal user interaction (UI:R). Successful exploitation allows the attacker to bypass security boundaries (Scope: Changed) and potentially access sensitive data or redirect users to malicious external domains. The vulnerability is easily exploitable via the network using the HTTP protocol.

Affected products

  • Oracle Macaron Tool 0.22.0

Timeline

  • 2026-05-06: disclosed: Initial disclosure by Oracle
  • 2026-05-06: advisory: NVD publication date

References