CVE-2026-46842: Medium severity Oracle Oracle REST Data Services vulnerability
Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle REST Data Services accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46842?
The severity of CVE-2026-46842 is medium with a score of 5.3.
How do I fix CVE-2026-46842?
To fix CVE-2026-46842, you should upgrade to a version of Oracle REST Data Services that is not affected, specifically above version 26.1.0.
Who is affected by CVE-2026-46842?
Organizations using Oracle REST Data Services versions 24.2.0 to 26.1.0 are affected by CVE-2026-46842.
What type of access is required to exploit CVE-2026-46842?
CVE-2026-46842 can be exploited by an unauthenticated attacker with network access via HTTPS.
What component is impacted by CVE-2026-46842?
CVE-2026-46842 impacts the Core component of Oracle REST Data Services.