CVE-2026-46829: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle REST Data Services. in Oracle Corporation Oracle REST Data Services
CVE-2026-46829 is a high-severity vulnerability in Oracle REST Data Services (Mongoapi component) versions 24. 2. 0 through 26. 1. 0. It allows an unauthenticated attacker with network access via HTTPS to cause a denial of service (DoS) by hanging or crashing the service repeatedly. The vulnerability has a CVSS 3. 1 base score of 7. 5, reflecting its impact on availability without affecting confidentiality or integrity. Oracle has addressed this vulnerability in its May 2026 Critical Security Patch Update (CSPU), which includes targeted security fixes for Oracle REST Data Services among other products.
AI Analysis
Technical Summary
CVE-2026-46829 affects Oracle REST Data Services versions 24.2.0 to 26.1.0, specifically the Mongoapi component. The vulnerability allows an unauthenticated attacker with network access over HTTPS to cause a hang or repeated crash of the service, resulting in a complete denial of service. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) indicates network attack vector, low attack complexity, no privileges or user interaction required, and high impact on availability only. Oracle has included a fix for this vulnerability in its May 2026 Critical Security Patch Update. The advisory emphasizes the importance of applying these patches promptly and notes that workarounds such as blocking network protocols or removing unnecessary privileges may reduce risk temporarily but do not fix the underlying issue.
Potential Impact
Successful exploitation of this vulnerability results in a complete denial of service (DoS) condition for Oracle REST Data Services, causing the service to hang or crash repeatedly. There is no impact on confidentiality or integrity. The vulnerability can be exploited remotely without authentication via HTTPS, making it a significant availability risk for affected systems.
Mitigation Recommendations
Oracle has released a security patch addressing CVE-2026-46829 as part of the May 2026 Critical Security Patch Update. Customers are strongly advised to apply this patch as soon as possible to remediate the vulnerability. Until the patch is applied, risk may be reduced by blocking network protocols required for the attack or by removing unnecessary privileges from users, but these measures may disrupt application functionality and are not permanent solutions. Oracle recommends testing any such changes in non-production environments. Staying on actively supported versions and promptly applying security patches is critical.
CVE-2026-46829: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle REST Data Services. in Oracle Corporation Oracle REST Data Services
Description
CVE-2026-46829 is a high-severity vulnerability in Oracle REST Data Services (Mongoapi component) versions 24. 2. 0 through 26. 1. 0. It allows an unauthenticated attacker with network access via HTTPS to cause a denial of service (DoS) by hanging or crashing the service repeatedly. The vulnerability has a CVSS 3. 1 base score of 7. 5, reflecting its impact on availability without affecting confidentiality or integrity. Oracle has addressed this vulnerability in its May 2026 Critical Security Patch Update (CSPU), which includes targeted security fixes for Oracle REST Data Services among other products.
CVSS v3.1
Score 7.5high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-46829 affects Oracle REST Data Services versions 24.2.0 to 26.1.0, specifically the Mongoapi component. The vulnerability allows an unauthenticated attacker with network access over HTTPS to cause a hang or repeated crash of the service, resulting in a complete denial of service. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) indicates network attack vector, low attack complexity, no privileges or user interaction required, and high impact on availability only. Oracle has included a fix for this vulnerability in its May 2026 Critical Security Patch Update. The advisory emphasizes the importance of applying these patches promptly and notes that workarounds such as blocking network protocols or removing unnecessary privileges may reduce risk temporarily but do not fix the underlying issue.
Potential Impact
Successful exploitation of this vulnerability results in a complete denial of service (DoS) condition for Oracle REST Data Services, causing the service to hang or crash repeatedly. There is no impact on confidentiality or integrity. The vulnerability can be exploited remotely without authentication via HTTPS, making it a significant availability risk for affected systems.
Mitigation Recommendations
Oracle has released a security patch addressing CVE-2026-46829 as part of the May 2026 Critical Security Patch Update. Customers are strongly advised to apply this patch as soon as possible to remediate the vulnerability. Until the patch is applied, risk may be reduced by blocking network protocols required for the attack or by removing unnecessary privileges from users, but these measures may disrupt application functionality and are not permanent solutions. Oracle recommends testing any such changes in non-production environments. Staying on actively supported versions and promptly applying security patches is critical.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- oracle
- Date Reserved
- 2026-05-18T15:55:10.304Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://www.oracle.com/security-alerts/cspumay2026.html","vendor":"Oracle"}]
Threat ID: 6a18aa2de29bf47b5027be53
Added to database: 5/28/2026, 8:48:45 PM
Last enriched: 5/28/2026, 9:04:40 PM
Last updated: 5/29/2026, 12:56:52 PM
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.