Junglewise Threat Intelligence

CVE-2026-46839: Oracle REST Data Services takeover in Core component

CVE-2026-46839 · Severity: critical · CVSS 9.9 · Published 2026-05-28

Technologies: Oracle REST Data Services. Vendors: Oracle.

Executive brief

Oracle REST Data Services, a tool that enables developers to use HTTP(S) and REST to work with Oracle Databases, contains a critical security vulnerability in its core component. A user with even low-level access to the network can exploit this flaw to take complete control of the service. Because this tool connects directly to database environments, a successful attack could lead to widespread data theft, service disruption, and potential unauthorized access to connected systems.

Technical details

A critical vulnerability exists in the Core component of Oracle REST Data Services (ORDS) versions 24.2.0 through 26.1.0. The flaw is categorized as easily exploitable and allows a low-privileged attacker with network access via HTTPS to compromise the service. Notably, the vulnerability includes a 'scope change' (S:C), indicating that an exploit can impact components beyond the ORDS environment itself, potentially affecting the underlying database or integrated Oracle products. Successful exploitation results in a complete takeover of the ORDS instance, impacting confidentiality, integrity, and availability. Users are advised to consult the Oracle May 2026 security alert for patching information.

Affected products

  • Oracle REST Data Services 24.2.0-26.1.0

Timeline

  • 2026-05-28: advisory: Initial disclosure by Oracle and NVD publication

References

Related threats