CVE-2026-46829: High severity Oracle Oracle REST Data Services vulnerability
Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle REST Data Services. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46829?
CVE-2026-46829 has a severity rating of high with a score of 7.5.
What versions are affected by CVE-2026-46829?
CVE-2026-46829 affects Oracle REST Data Services versions 24.2.0 to 26.1.0.
What type of access is required to exploit CVE-2026-46829?
An unauthenticated attacker with network access via HTTPS can exploit CVE-2026-46829.
What is the potential impact of exploiting CVE-2026-46829?
Exploiting CVE-2026-46829 can lead to compromise of Oracle REST Data Services.
How can I mitigate CVE-2026-46829?
To mitigate CVE-2026-46829, it's recommended to update Oracle REST Data Services to a version not affected by the vulnerability.