Junglewise Threat Intelligence

CVE-2026-46840: Oracle REST Data Services remote compromise in Backend-as-a-Service

CVE-2026-46840 · Severity: critical · CVSS 10 · Published 2026-05-28

Technologies: Oracle REST Data Services. Vendors: Oracle.

Executive brief

Oracle REST Data Services, a tool used to bridge HTTPS requests to Oracle Databases, contains a critical vulnerability in its Backend-as-a-Service component. An unauthenticated attacker can remotely take full control of the service over the network. This could lead to a total compromise of the data services and potentially impact connected database systems and applications.

Technical details

This vulnerability exists in the Backend-as-a-Service component of Oracle REST Data Services (ORDS). It is classified as easily exploitable, requiring no authentication or user interaction (AV:N/AC:L/PR:N/UI:N). The flaw allows a remote attacker to gain full control over the ORDS instance via HTTPS. Notably, the CVSS score includes a 'Scope Change' (S:C), indicating that an exploit can impact components beyond the immediate ORDS environment, such as the underlying database or connected applications. Affected versions range from 24.2.0 through 26.1.0.

Affected products

  • Oracle REST Data Services 24.2.0-26.1.0

Timeline

  • 2026-05-28: disclosed
  • 2026-05-28: advisory: NVD publication date

References

Related threats