Junglewise Threat Intelligence

CVE-2026-46830: Oracle REST Data Services information disclosure in Mongoapi

CVE-2026-46830 · Severity: medium · CVSS 5.3 · Published 2026-05-28

Technologies: Oracle REST Data Services. Vendors: Oracle.

Executive brief

Oracle REST Data Services, a tool that enables developers to use HTTP(S) and REST to interact with Oracle Databases, contains a security vulnerability in its Mongo API component. An unauthenticated attacker can exploit this flaw over the network to gain unauthorized access to sensitive data. This could lead to the exposure of business information stored within the database environment.

Technical details

A vulnerability in the Mongoapi component of Oracle REST Data Services (versions 24.2.0 through 26.1.0) allows for unauthorized data access. The flaw is categorized as easily exploitable and can be triggered by an unauthenticated attacker with network access via HTTPS. Successful exploitation results in a loss of confidentiality, specifically allowing the attacker to read a subset of the data managed by the service. The vulnerability has a CVSS 3.1 base score of 5.3, reflecting its impact on confidentiality without affecting integrity or availability.

Affected products

  • Oracle REST Data Services 24.2.0-26.1.0

Timeline

  • 2026-05-28: advisory: Initial disclosure by Oracle and NVD publication.

References

Related threats