Junglewise Threat Intelligence

CVE-2026-46841: Oracle REST Data Services information disclosure in General component

CVE-2026-46841 · Severity: medium · CVSS 5.3 · Published 2026-05-28

Technologies: Oracle REST Data Services. Vendors: Oracle.

Executive brief

Oracle REST Data Services, a tool that enables developers to use HTTP(S) and REST to interact with Oracle Databases, contains a vulnerability that allows unauthorized data access. An unauthenticated attacker can remotely read a subset of the data managed by the service without needing any special credentials. This could lead to the exposure of sensitive business information or internal database metadata.

Technical details

This vulnerability in the 'General' component of Oracle REST Data Services (ORDS) is classified as an information disclosure flaw. It is easily exploitable by an unauthenticated attacker with network access via HTTPS. The root cause is not specified in the advisory, but the impact is limited to unauthorized read access (Confidentiality) of a subset of ORDS-accessible data, with no impact on data integrity or service availability. The vulnerability affects supported versions 24.2.0 through 26.1.0. Users are advised to refer to the Oracle Security Alert for patching instructions.

Affected products

  • Oracle REST Data Services 24.2.0-26.1.0

Timeline

  • 2026-05-28: disclosed: Initial publication of the CVE record.
  • 2026-05-28: advisory: Oracle released the security alert.

References

Related threats