Description
Vulnerability in Oracle REST Data Services (component: General). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle REST Data Services accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-05-28
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A CWE-200 information‑exposure flaw in the general component of Oracle REST Data Services allows an unauthenticated attacker who can reach the service over HTTPS to read a subset of data exposed by the service. The flaw does not modify data or disrupt service operation. Impact is limited to confidentiality, as reflected by the CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N.

Affected Systems

Oracle REST Data Services versions 24.2.0 through 26.1.0 are affected. The vulnerability resides in the general component of the product.

Risk and Exploitability

The CVSS base score of 5.3 indicates a medium severity. However, the EPSS score of <1% suggests a very low probability of exploitation in the wild. The lack of authentication requirement means a network attacker could easily attempt the attack, but the combination of a low EPSS and the need for direct HTTPS connectivity mitigates the overall risk. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on May 29, 2026 at 19:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or upgrade Oracle REST Data Services to a version beyond 26.1.0.
  • Restrict inbound HTTPS traffic to the service using firewall rules or network segmentation so that only trusted sources can reach it.
  • Configure the service to enforce proper access control and authorization before exposing data, ensuring that sensitive data is not returned without authentication.

Generated by OpenCVE AI on May 29, 2026 at 19:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 29 May 2026 20:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Data Disclosure in Oracle REST Data Services

Fri, 29 May 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Read Access via Unauthenticated HTTPS in Oracle REST Data Services
Weaknesses CWE-284
CWE-285

Fri, 29 May 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 28 May 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Read Access via Unauthenticated HTTPS in Oracle REST Data Services
Weaknesses CWE-284
CWE-285

Thu, 28 May 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle REST Data Services (component: General). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle REST Data Services accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle rest Data Services
CPEs cpe:2.3:a:oracle:rest_data_services:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle rest Data Services
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Rest Data Services
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-05-29T15:17:23.952Z

Reserved: 2026-05-18T15:55:10.305Z

Link: CVE-2026-46841

cve-icon Vulnrichment

Updated: 2026-05-29T15:17:17.984Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-05-28T21:16:33.960

Modified: 2026-05-29T16:16:31.020

Link: CVE-2026-46841

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T20:00:05Z

Weaknesses