Executive brief
Oracle REST Data Services, a tool used to bridge HTTPS requests to Oracle Databases, contains a critical vulnerability in its Backend-as-a-Service component. An unauthenticated attacker can remotely take full control of the service over the network. This could lead to a total compromise of the data services and potentially impact connected database systems and applications.
Technical details
This vulnerability exists in the Backend-as-a-Service component of Oracle REST Data Services (ORDS). It is classified as easily exploitable, requiring no authentication or user interaction (AV:N/AC:L/PR:N/UI:N). The flaw allows a remote attacker to gain full control over the ORDS instance via HTTPS. Notably, the CVSS score includes a 'Scope Change' (S:C), indicating that an exploit can impact components beyond the immediate ORDS environment, such as the underlying database or connected applications. Affected versions range from 24.2.0 through 26.1.0.
Affected products
- Oracle REST Data Services 24.2.0-26.1.0
Timeline
- 2026-05-28: disclosed
- 2026-05-28: advisory: NVD publication date