CVE-2026-21997
Unauthorized Data Modification Vulnerability in Oracle Empirica Signal
Publication date: 2026-04-21
Last updated on: 2026-05-01
Assigner: Oracle
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| oracle | life_sciences_empirica_signal | From 9.2.1 (inc) to 9.2.3 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the Oracle Life Sciences Empirica Signal product, specifically in versions 9.2.1 to 9.2.3. It allows a low privileged attacker with network access via HTTP to exploit the system easily. The attacker can compromise the product by gaining unauthorized abilities to create, delete, or modify critical data or any data accessible within Oracle Life Sciences Empirica Signal. Additionally, the attacker can read some subset of the accessible data without authorization.
How can this vulnerability impact me? :
The impact of this vulnerability includes unauthorized creation, deletion, or modification of critical data, which can severely affect the integrity of the system. There is also unauthorized read access to some data, which compromises confidentiality. Because the vulnerability allows such significant unauthorized access, it can lead to data breaches, loss of data integrity, and potentially affect other related products due to scope change.
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
The vulnerability allows unauthorized creation, deletion, modification, and read access to critical data within Oracle Life Sciences Empirica Signal. Such unauthorized access and data manipulation could lead to non-compliance with data protection standards and regulations like GDPR and HIPAA, which require strict controls over data confidentiality, integrity, and access.
Specifically, the confidentiality and integrity impacts indicated by the CVSS score (8.5) suggest that sensitive data could be exposed or altered without authorization, potentially violating regulatory requirements for protecting personal and health information.