Junglewise Threat Intelligence

CVE-2026-46775: Oracle REST Data Services takeover in Core component

CVE-2026-46775 · Severity: critical · CVSS 9.9 · Published 2026-05-28

Technologies: Oracle REST Data Services. Vendors: Oracle.

Executive brief

Oracle REST Data Services, a tool that enables developers to use HTTP(S) and REST to work with Oracle Databases, contains a critical security vulnerability in its core component. An attacker with low-level access to the network can exploit this flaw to take complete control of the service. This could lead to unauthorized access to sensitive database information, data modification, or a total disruption of services that rely on these web interfaces.

Technical details

A critical vulnerability exists in the Core component of Oracle REST Data Services (ORDS). The flaw is categorized as easily exploitable and allows a low-privileged attacker with network access via HTTPS to compromise the system. The vulnerability is notable for a 'scope change' (S:C), meaning a successful exploit can impact products beyond ORDS itself, potentially leading to a full takeover of the service and its associated data. The CVSS 3.1 base score is 9.9, reflecting high impacts on confidentiality, integrity, and availability. Users are advised to refer to the Oracle May 2026 security alert for patching information.

Affected products

  • Oracle REST Data Services 24.2.0-26.1.0

Timeline

  • 2026-05-28: advisory: Initial disclosure by Oracle and NVD publication.

References

Related threats