Executive brief
Oracle Autonomous Health Framework is a diagnostic tool used to monitor and troubleshoot Oracle database infrastructure. A vulnerability in its Trace File Analyzer component allows a low-privileged local user to delete, modify, or create critical data, and can cause the service to crash completely. Attackers could use this to corrupt database diagnostics, compromise data integrity, or disable monitoring capabilities across the infrastructure.
Technical details
This vulnerability in Oracle Autonomous Health Framework's Trace File Analyzer component is an easily exploitable local privilege escalation affecting versions 26.0–26.5.2. The vulnerability requires local logon access and low privileges to execute, with no user interaction needed. A successful attack allows an attacker to create, delete, or modify critical data and trigger denial-of-service conditions affecting the framework and potentially other products on the infrastructure (scope change). The CVSS 3.1 vector (AV:L/AC:L/PR:L/UI:N/S:C) confirms local attack vector with low complexity and scope crossing to other systems. Fix status and specific patched versions are not detailed in the available advisory material.
Affected products
- Oracle Autonomous Health Framework 26.0–26.1.0, 26.2.0, 26.3.1, 26.5.0, 26.5.2
Timeline
- 2026-08-18: disclosed