Junglewise Threat Intelligence

CVE-2026-46842: Oracle REST Data Services unauthorized data modification in Core component

CVE-2026-46842 · Severity: medium · CVSS 5.3 · Published 2026-05-28

Technologies: Oracle REST Data Services. Vendors: Oracle.

Executive brief

Oracle REST Data Services, a tool that enables developers to use HTTP(S) and REST to interact with Oracle Databases, contains a vulnerability in its core component. An unauthenticated attacker can exploit this over the network to modify, insert, or delete certain data. This could lead to unauthorized changes to business records or data corruption without requiring any user interaction.

Technical details

This vulnerability exists in the Core component of Oracle REST Data Services (ORDS). It is classified as an integrity-impacting flaw that allows an unauthenticated remote attacker to compromise the system via HTTPS. Successful exploitation enables the attacker to perform unauthorized update, insert, or delete operations on a subset of data accessible through ORDS. The vulnerability has a CVSS 3.1 base score of 5.3, reflecting low integrity impact with no impact on confidentiality or availability. Affected versions range from 24.2.0 to 26.1.0.

Affected products

  • Oracle REST Data Services 24.2.0-26.1.0

Timeline

  • 2026-05-28: advisory: Initial advisory published by Oracle

References

Related threats