QSearchQSearch

CVE-2026-46840

10.0 CRITICAL

Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service)

Published: 2026-05-28 · Last updated: 2026-06-04

Severity and scoring

CVSS
10.0 CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE
CWE-284, CWE-287, CWE-306

Affected products

VendorProduct
oraclerest_data_services

Description

Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. While the vulnerability is in Oracle REST Data Services, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle REST Data Services. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-46843 Vulnerability in Oracle REST Data Services (component: Core) (5.3 MEDIUM)
  • CVE-2026-46842 Vulnerability in Oracle REST Data Services (component: Core) (5.3 MEDIUM)
  • CVE-2026-46841 Vulnerability in Oracle REST Data Services (component: General) (5.3 MEDIUM)
  • CVE-2026-46839 Vulnerability in Oracle REST Data Services (component: Core) (9.9 CRITICAL)
  • CVE-2026-46837 Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Security) (8.8 HIGH)

Same CWE

  • CVE-2026-47166 ImageMagick is free and open-source software used for editing and manipulating digital images (5.7 MEDIUM)
  • CVE-2026-46695 Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to ru... (10.0 CRITICAL)
  • CVE-2026-46705 Russh is a Rust SSH client & server library (5.3 MEDIUM)
  • CVE-2022-48575 A person with access to a Mac may be able to bypass Login Window (3.5 LOW)
  • CVE-2026-50564 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes (9.9 CRITICAL)