Executive brief
A vulnerability exists in Oracle REST Data Services, a tool used to bridge HTTPS requests to Oracle Databases. An attacker with low-level user credentials can exploit this flaw over the network to gain unauthorized access to sensitive business data. This could result in the theft, modification, or deletion of critical information stored within the database environment.
Technical details
A vulnerability in the Core component of Oracle REST Data Services (ORDS) affects versions 24.2.0 through 26.1.0. The flaw is easily exploitable by a low-privileged attacker with network access via HTTPS. While the specific CWE is not identified in the advisory, the impact allows for unauthorized creation, deletion, or modification of all ORDS-accessible data. The attack does not require user interaction and has a high impact on confidentiality and integrity, though it does not directly impact service availability according to the CVSS vector. Users are advised to refer to the Oracle Security Alert for patching information.
Affected products
- Oracle REST Data Services 24.2.0-26.1.0
Timeline
- 2026-05-28: disclosed: Initial disclosure by Oracle and NVD publication.