CVE-2026-35266
Unauthorized Data Access in Oracle REST Data Services
Publication date: 2026-05-28
Last updated on: 2026-05-28
Assigner: Oracle
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| oracle | rest_data_services | From 24.2.0 (inc) to 26.1.0 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the Core component of Oracle REST Data Services versions 24.2.0 through 26.1.0. It is difficult to exploit and requires a low privileged attacker with network access via HTTPS. Additionally, successful exploitation requires human interaction from someone other than the attacker.
If exploited, the attacker can compromise Oracle REST Data Services, potentially affecting other related products as well. The attacker may gain unauthorized abilities such as creating, deleting, or modifying critical data, accessing all data accessible through Oracle REST Data Services, and causing a partial denial of service (partial DOS) of the service.
How can this vulnerability impact me? :
The impact of this vulnerability includes unauthorized creation, deletion, or modification of critical data within Oracle REST Data Services. An attacker could gain unauthorized access to all data accessible through the service.
Additionally, the vulnerability can lead to a partial denial of service (partial DOS), affecting the availability of Oracle REST Data Services.
Overall, the confidentiality, integrity, and availability of the affected system can be significantly compromised.
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
This vulnerability in Oracle REST Data Services allows unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to critical or all accessible data. Such unauthorized access and data manipulation can lead to violations of data protection and privacy regulations like GDPR and HIPAA, which require strict controls over data confidentiality, integrity, and availability.
Successful exploitation could result in data breaches or data integrity issues, potentially causing non-compliance with these standards that mandate protection of sensitive information and timely detection and response to security incidents.