Impact
The flaw resides in the Trace File Analyzer component of Oracle Autonomous Health Framework and allows an attacker with local high‑privilege access, who can co‑operate with a third‑party user to trigger the vulnerable functionality, to create, modify, or delete critical data and to cause the framework to hang or crash repeatedly, thereby compromising both integrity and availability.
Affected Systems
Oracle Autonomous Health Framework deployments running the following versions are affected: 26-26.1.0, 26.2.0, 26.3.1, 26.5.0, and 26.5.2. These releases contain the vulnerable Trace File Analyzer component.
Risk and Exploitability
The CVSS v3.1 base score of 7.4 reflects significant integrity and availability impact and the vector (AV:L/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:H) indicates the attack originates locally with low complexity, high‑privileged users, and requires a user interaction from a non‑attacking third party. The EPSS score of less than 1% suggests a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. However, because the scope shift allows potential control over other Oracle products on the same infrastructure, any environment where high‑privileged local accounts exist is still a valid target for this local exploit.
OpenCVE Enrichment