Executive brief
Oracle REST Data Services, a tool that enables developers to use HTTP(S) and REST to work with Oracle Databases, contains a critical security vulnerability in its core component. An attacker with low-level access to the network can exploit this flaw to take complete control of the service. This could lead to unauthorized access to sensitive database information, data modification, or a total disruption of services that rely on these web interfaces.
Technical details
A critical vulnerability exists in the Core component of Oracle REST Data Services (ORDS). The flaw is categorized as easily exploitable and allows a low-privileged attacker with network access via HTTPS to compromise the system. The vulnerability is notable for a 'scope change' (S:C), meaning a successful exploit can impact products beyond ORDS itself, potentially leading to a full takeover of the service and its associated data. The CVSS 3.1 base score is 9.9, reflecting high impacts on confidentiality, integrity, and availability. Users are advised to refer to the Oracle May 2026 security alert for patching information.
Affected products
- Oracle REST Data Services 24.2.0-26.1.0
Timeline
- 2026-05-28: advisory: Initial disclosure by Oracle and NVD publication.