CVE-2026-22010: High severity Oracle Oracle Financial Services Analytical Applications Infrastructure vulnerability
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22010?
CVE-2026-22010 is classified as an easily exploitable vulnerability that can be leveraged by unauthenticated attackers.
How do I fix CVE-2026-22010?
To mitigate CVE-2026-22010, upgrade to a patched version of Oracle Financial Services Analytical Applications Infrastructure that is not affected by this vulnerability.
Which versions are affected by CVE-2026-22010?
The affected versions of Oracle Financial Services Analytical Applications Infrastructure are 8.0.7.9, 8.0.8.7, and 8.1.2.5.
Can CVE-2026-22010 be exploited remotely?
Yes, CVE-2026-22010 can be exploited remotely by unauthenticated attackers.
What component of Oracle is impacted by CVE-2026-22010?
CVE-2026-22010 impacts the Platform component of the Oracle Financial Services Analytical Applications Infrastructure product.