CVE-2026-21978: Medium severity Oracle FLEXCUBE Universal Banking vulnerability
Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Relationship Pricing). Supported versions that are affected are 14.0.0.0.0-14.8.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle FLEXCUBE Universal Banking accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21978?
CVE-2026-21978 is classified as a medium severity vulnerability.
How do I fix CVE-2026-21978?
To fix CVE-2026-21978, Oracle recommends applying the latest security patches for Oracle FLEXCUBE Universal Banking.
Who is affected by CVE-2026-21978?
CVE-2026-21978 affects users of Oracle FLEXCUBE Universal Banking versions 14.0.0.0.0 to 14.8.0.0.0.
What is the attack vector for CVE-2026-21978?
CVE-2026-21978 can be exploited by low privileged attackers with network access via HTTP.
What components of Oracle FLEXCUBE Universal Banking are affected by CVE-2026-21978?
CVE-2026-21978 specifically affects the Relationship Pricing component in Oracle FLEXCUBE Universal Banking.