Description
Vulnerability in the Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit product of Oracle Open Source Projects (component: Desktop). The supported version that is affected is 0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit. Successful attacks of this vulnerability can result in takeover of Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-03-17
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution via HTTP
Action: Immediate Patch
AI Analysis

Impact

The flaw in Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit version 0.3.0 allows an unauthenticated attacker to send specially crafted HTTP requests to the application’s desktop component. This missing access control, identified as CWE‑284, leads to full compromise of the system, enabling the attacker to execute arbitrary code, read or delete confidential data, and permanently disrupt service availability. The vulnerability carries a CVSS 3.1 base score of 9.8, indicating critical severity with high impacts on confidentiality, integrity, and availability.

Affected Systems

Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit from Oracle Corporation is the only product listed as affected. The specific vulnerable release is 0.3.0, part of the Oracle Open Source Projects suite, and the issue is limited to the desktop component of the toolkit.

Risk and Exploitability

The CVSS score of 9.8 marks this issue as critical, and its EPSS score of less than 1 % suggests that while exploitation is currently not common, the potential for a successful attack remains high once network access is established. The flaw is not currently listed in CISA’s KEV catalog, but its lack of authentication and the ability to achieve remote code execution make it a high‑risk vulnerability. Based on the description, the likely attack vector is the exposed HTTP interface; an attacker can exploit the flaw from any network that can reach the application’s HTTP port.

Generated by OpenCVE AI on April 2, 2026 at 13:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available Oracle patch or upgrade to a non‑affected version of Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit.
  • Restrict network access to the application’s HTTP endpoint so that only trusted systems can communicate with it.
  • Monitor system logs for unauthorized HTTP requests or other indicators of attempted exploitation.

Generated by OpenCVE AI on April 2, 2026 at 13:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via HTTP in Oracle Edge Cloud Infrastructure Designer 0.3.0

Thu, 02 Apr 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Oracle okit
CPEs cpe:2.3:a:oracle:okit:0.3.0:*:*:*:desktop:*:*:*
Vendors & Products Oracle okit

Tue, 24 Mar 2026 13:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via HTTP in Oracle Edge Cloud Infrastructure Designer 0.3.0

Wed, 18 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 18 Mar 2026 04:30:00 +0000


Wed, 18 Mar 2026 04:15:00 +0000


Tue, 17 Mar 2026 23:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit product of Oracle Open Source Projects (component: Desktop). The supported version that is affected is 0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit. Successful attacks of this vulnerability can result in takeover of Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle edge Cloud Infrastructure Designer And Visualisation Toolkit
CPEs cpe:2.3:a:oracle:edge_cloud_infrastructure_designer_and_visualisation_toolkit:0.3.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle edge Cloud Infrastructure Designer And Visualisation Toolkit
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Edge Cloud Infrastructure Designer And Visualisation Toolkit Okit
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-03-18T14:33:31.192Z

Reserved: 2026-01-05T18:07:34.718Z

Link: CVE-2026-21994

cve-icon Vulnrichment

Updated: 2026-03-18T14:33:26.445Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-17T23:16:17.310

Modified: 2026-04-02T12:27:23.640

Link: CVE-2026-21994

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-02T20:23:34Z

Weaknesses