Executive brief
A vulnerability exists in Oracle REST Data Services, a tool used to bridge HTTPS requests to Oracle Databases. A low-privileged attacker could potentially gain full access to sensitive data or modify critical information, though the attack is difficult to perform and requires a legitimate user to interact with a malicious link or site. If successful, this could lead to a significant data breach or a partial disruption of database services.
Technical details
A vulnerability in the Core component of Oracle REST Data Services (versions 24.2.0 through 26.1.0) allows a low-privileged attacker with network access via HTTPS to compromise the system. The vulnerability is characterized by a high attack complexity (AC:H) and requires human interaction (UI:R) from a victim other than the attacker. Due to a scope change (S:C), the exploit may impact products beyond the REST Data Services themselves. Successful exploitation can result in unauthorized creation, deletion, or modification of all accessible data, as well as a partial denial of service. The CVSS vector indicates high impacts to confidentiality and integrity, with a low impact on availability.
Affected products
- Oracle REST Data Services 24.2.0-26.1.0
Timeline
- 2026-05-28: disclosed: Initial disclosure by Oracle and NVD publication.