Impact
Vulnerability in the Cluster Health Analyzer component of Oracle Autonomous Health Framework permits a low‑privileged attacker who has access to the network segment physically attached to the hosting hardware to create, delete, or modify critical data without user interaction. The flaw results in substantial confidentiality and integrity damage and enables the attacker to compromise all data accessible via the framework. The CVSS vector indicates a scope change, implying that exploitation may impact other dependent Oracle products as well.
Affected Systems
The affected vendor is Oracle Corporation, specifically the Oracle Autonomous Health Framework. Versions 26-26.1.0, 26.2.0, 26.3.1, 26.5.0, and 26.5.2 are vulnerable according to the advisory.
Risk and Exploitability
The CVSS 3.1 base score of 7.7 signals a high severity, while the EPSS score of < 1% indicates a very low exploitation probability and KEV is not listed. Based on the description, it is inferred that attackers require physical proximity but no privileged credentials beyond low‑level access, and the likely attack vector is adjacent network. Because the vulnerability introduces a scope change, a successful exploitation can cascade to other systems within the same environment, raising the overall risk. Based on the CVSS vector, it is inferred that the scope change may affect other dependent Oracle products as well. The lack of user interaction reduces the likelihood of accidental exploitation but does not eliminate it, especially in environments where physical network access is not tightly controlled.
OpenCVE Enrichment