Impact
The vulnerability resides within the Developer triaging platform of Oracle Autonomous Health Framework and permits a local, high-privileged attacker who is logged into the host infrastructure to compromise the entire framework. Successful exploitation requires human interaction from a user other than the attacker, an element explicitly noted in the description. Once exploited, the attacker obtains full control of the framework, achieving confidentiality, integrity, and availability impact, as reflected by the CVSS vector (AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H) and the referenced CWE-284.
Affected Systems
Oracle Autonomous Health Framework versions 26.0.0, 26.1.0, and 26.2.0 are affected. The flaw is specific to the Developer triaging platform component within these releases.
Risk and Exploitability
The EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS base score of 6.3 reflects moderate severity, yet the potential impact is high because of the complete takeover capability. Exploitation requires local high-privilege access and an additional human interaction, limiting automated attacks but still posing a significant threat where privileged users have access to the host environment.
OpenCVE Enrichment