Description
Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle REST Data Services. While the vulnerability is in Oracle REST Data Services, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle REST Data Services. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-05-28
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle REST Data Services Core enables a low‑privileged attacker who can reach the service over HTTPS to fully compromise the application. The vulnerability allows disclosure of all data, modification of any data, and complete control of the service, effectively resulting in a full takeover. It carries a CVSS 3.1 Base Score of 9.9 and impacts confidentiality, integrity, and availability.

Affected Systems

Affected product: Oracle REST Data Services. Versions impacted are 24.2.0 through 26.1.0. The issue resides in the Core component of the product.

Risk and Exploitability

The exploit is considered easily actionable; the attack vector is via network‑bound HTTPS traffic and requires only low or no privileges. Because the vulnerability changes scope, successful compromise could affect other Oracle products that rely on the service. The current EPSS score is not available, and the vulnerability is not yet listed in CISA KEV, but the high CVSS combined with the potential for complete takeover underscores a serious risk if left unmitigated.

Generated by OpenCVE AI on May 28, 2026 at 21:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle REST Data Services to the latest version that contains the fix for CVE‑2026‑46839.
  • Restrict inbound traffic to the REST Data Services instances to only trusted hosts or networks and enforce strong authentication and access controls.
  • Apply network segmentation or a firewall rule to limit exposure of the service from untrusted networks.
  • If a patch is not immediately available, disable or restrict the Core component’s exposed HTTPS endpoints until remediation is applied.

Generated by OpenCVE AI on May 28, 2026 at 21:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 29 May 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 28 May 2026 21:45:00 +0000

Type Values Removed Values Added
Title Oracle REST Data Services Core Remote Takeover via HTTPS
Weaknesses CWE-284
CWE-287

Thu, 28 May 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle REST Data Services. While the vulnerability is in Oracle REST Data Services, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle REST Data Services. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle rest Data Services
CPEs cpe:2.3:a:oracle:rest_data_services:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle rest Data Services
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Rest Data Services
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-05-29T15:05:36.372Z

Reserved: 2026-05-18T15:55:10.305Z

Link: CVE-2026-46839

cve-icon Vulnrichment

Updated: 2026-05-29T15:05:32.765Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-05-28T21:16:33.707

Modified: 2026-05-29T16:16:30.780

Link: CVE-2026-46839

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-28T23:30:26Z

Weaknesses