


Perceptive Security
SOC/SIEM Consultancy

Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows l…
Published:
27 mei 2026 om 22:00:00
Alert date:
28 mei 2026 om 22:04:22
Source:
nvd.nist.gov
Enterprise Applications, Database & Storage
A critical vulnerability (CVE-2026-46775) has been discovered in Oracle REST Data Services Core component affecting versions 24.2.0-26.1.0. The vulnerability is easily exploitable and allows low-privileged attackers with network access via HTTPS to compromise the service. Successful exploitation can result in complete takeover of Oracle REST Data Services and may significantly impact additional products due to scope change. The vulnerability has a CVSS 3.1 Base Score of 9.9, indicating maximum impact on confidentiality, integrity, and availability. The attack vector is network-based with low complexity, requiring only low privileges and no user interaction.
Technical details
Mitigation steps:
Affected products:
Oracle REST Data Services
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-46775
https://www.oracle.com/security-alerts/cspumay2026.html
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
