Impact
Oracle Autonomous Health Framework’s Trace File Analyzer component contains a remotely exploitable flaw that allows attackers with network access over HTTP and low privileges to gain unauthorized access to critical data and, in some cases, to modify or delete that data. The vulnerability was evaluated with a CVSS 3.1 base score of 8.5, indicating significant confidentiality and integrity impacts and a revoked scope change.
Affected Systems
Oracle Corporation’s Autonomous Health Framework is affected. The vulnerability applies to releases 26-26.1.0, 26.2.0, 26.3.1, 26.5.0, and 26.5.2. No other products are listed as affected in the official CVE data.
Risk and Exploitability
Because the flaw is accessible over the network with only low‑privilege credentials, it is easily exploitable by attackers who can reach the HTTP endpoint. The EPSS score indicates a very low exploitation probability (< 1%) and the issue is not listed in CISA’s KEV catalog, but its high CVSS score and potential scope expansion make it a high‑risk threat that should be addressed promptly.
OpenCVE Enrichment