Description
Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle REST Data Services, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle REST Data Services accessible data as well as unauthorized access to critical data or complete access to all Oracle REST Data Services accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle REST Data Services. CVSS 3.1 Base Score 7.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:L).
Published: 2026-05-28
Score: 7.9 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A low‑privileged attacker with network access over HTTPS can influence Oracle REST Data Services, provided a user other than the attacker interacts with the application. The flaw, identified as CWE‑352 (Cross‑Site Request Forgery) and CWE‑400 (Uncontrolled Resource Consumption), permits unauthorized creation, deletion, or modification of critical data and grants full read access to all data exposed through the service. Additionally, the attacker can cause a partial denial of service by exhausting server resources. These vulnerabilities affect confidentiality, integrity, and availability with a CVSS 3.1 base score of 7.9.

Affected Systems

Oracle REST Data Services supplied by Oracle Corporation is affected for versions 24.2.0 through 26.1.0. The vulnerability is exploitable over HTTPS across the network. The CVSS vector indicates a scope change, meaning exploitation may impact other Oracle products that interact with the REST layer.

Risk and Exploitability

The CVSS score reflects high confidentiality and integrity risk with a low availability impact, and the EPSS of <1% indicates a very low exploitation probability at present. The requirement for user interaction reduces the likelihood of widespread attacks, but the potential for data loss and service disruption warrants prompt action. The issue is not listed in the CISA KEV catalog, so no confirmed active exploitation is reported yet.

Generated by OpenCVE AI on June 3, 2026 at 19:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle REST Data Services patch or upgrade to a version newer than 26.1.0 that contains the fix.
  • Restrict network access to the REST endpoint by placing it behind a firewall or VPN and limiting exposure to trusted IP ranges.
  • Enforce strict authentication and limit user privileges, removing rights that are not required to use the REST API.

Generated by OpenCVE AI on June 3, 2026 at 19:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 03 Jun 2026 19:45:00 +0000

Type Values Removed Values Added
Title Cross‑Site Request Forgery Enables Unauthorized Data Manipulation and Partial Denial of Service in Oracle REST Data Services

Wed, 03 Jun 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Fri, 29 May 2026 20:45:00 +0000

Type Values Removed Values Added
Title Cross‑Site Request Forgery Enables Unauthorized Data Manipulation and Partial Denial of Service in Oracle REST Data Services

Fri, 29 May 2026 19:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service in Oracle REST Data Services via HTTPS
Weaknesses CWE-284

Fri, 29 May 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-352
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 28 May 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service in Oracle REST Data Services via HTTPS
Weaknesses CWE-284

Thu, 28 May 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle REST Data Services, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle REST Data Services accessible data as well as unauthorized access to critical data or complete access to all Oracle REST Data Services accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle REST Data Services. CVSS 3.1 Base Score 7.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:L).
First Time appeared Oracle
Oracle rest Data Services
CPEs cpe:2.3:a:oracle:rest_data_services:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle rest Data Services
References
Metrics cvssV3_1

{'score': 7.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:L'}


Subscriptions

Oracle Rest Data Services
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-05-29T16:47:13.650Z

Reserved: 2026-04-01T20:03:40.835Z

Link: CVE-2026-35266

cve-icon Vulnrichment

Updated: 2026-05-29T16:45:49.567Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-28T21:16:29.330

Modified: 2026-06-03T18:03:19.167

Link: CVE-2026-35266

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-03T19:30:36Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)

  • CWE-400

    Uncontrolled Resource Consumption