Executive brief
Oracle REST Data Services, a tool that enables developers to use HTTP(S) and REST to interact with Oracle Databases, contains a vulnerability that allows unauthorized data access. An unauthenticated attacker can remotely read a subset of the data managed by the service without needing any special credentials. This could lead to the exposure of sensitive business information or internal database metadata.
Technical details
This vulnerability in the 'General' component of Oracle REST Data Services (ORDS) is classified as an information disclosure flaw. It is easily exploitable by an unauthenticated attacker with network access via HTTPS. The root cause is not specified in the advisory, but the impact is limited to unauthorized read access (Confidentiality) of a subset of ORDS-accessible data, with no impact on data integrity or service availability. The vulnerability affects supported versions 24.2.0 through 26.1.0. Users are advised to refer to the Oracle Security Alert for patching instructions.
Affected products
- Oracle REST Data Services 24.2.0-26.1.0
Timeline
- 2026-05-28: disclosed: Initial publication of the CVE record.
- 2026-05-28: advisory: Oracle released the security alert.