CVE-2026-46842: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle REST Data Services accessible data. in Oracle Corporation Oracle REST Data Services
CVE-2026-46842 is a medium severity vulnerability in Oracle REST Data Services versions 24. 2. 0 through 26. 1. 0. It allows an unauthenticated attacker with network access via HTTPS to perform unauthorized update, insert, or delete operations on accessible data. The vulnerability impacts data integrity but does not affect confidentiality or availability. Oracle has included this vulnerability in its May 2026 Critical Security Patch Update advisory, which provides patches for affected versions. Oracle strongly recommends applying these patches promptly to mitigate the risk. No known exploits in the wild have been reported at this time.
AI Analysis
Technical Summary
This vulnerability affects the Core component of Oracle REST Data Services (versions 24.2.0 to 26.1.0). It allows an unauthenticated attacker with network access over HTTPS to compromise the service by performing unauthorized data modification operations such as update, insert, or delete. The CVSS 3.1 base score is 5.3, reflecting a medium severity primarily due to integrity impact without confidentiality or availability impact. Oracle has addressed this vulnerability in its May 2026 Critical Security Patch Update, which includes 35 security patches across multiple products including Oracle REST Data Services. The vendor advisory emphasizes the importance of applying these patches without delay and offers guidance on temporary risk reduction measures such as blocking network protocols or removing unnecessary privileges, though these are not long-term solutions.
Potential Impact
Successful exploitation allows unauthorized modification of some accessible data in Oracle REST Data Services, impacting data integrity. There is no impact on confidentiality or availability according to the CVSS vector. No known exploits have been reported in the wild. The vulnerability can be exploited remotely without authentication over HTTPS.
Mitigation Recommendations
Oracle has released patches for this vulnerability as part of the May 2026 Critical Security Patch Update. Customers are strongly advised to apply these security patches as soon as possible to remediate the vulnerability. Until patches are applied, risk may be partially reduced by blocking network protocols required for the attack or by removing unnecessary privileges from users, but these are not substitutes for patching. Oracle recommends testing any such mitigations in non-production environments before deployment. Staying on supported product versions and promptly applying security updates is critical to maintaining security.
CVE-2026-46842: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle REST Data Services accessible data. in Oracle Corporation Oracle REST Data Services
Description
CVE-2026-46842 is a medium severity vulnerability in Oracle REST Data Services versions 24. 2. 0 through 26. 1. 0. It allows an unauthenticated attacker with network access via HTTPS to perform unauthorized update, insert, or delete operations on accessible data. The vulnerability impacts data integrity but does not affect confidentiality or availability. Oracle has included this vulnerability in its May 2026 Critical Security Patch Update advisory, which provides patches for affected versions. Oracle strongly recommends applying these patches promptly to mitigate the risk. No known exploits in the wild have been reported at this time.
CVSS v3.1
Score 5.3medium
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability affects the Core component of Oracle REST Data Services (versions 24.2.0 to 26.1.0). It allows an unauthenticated attacker with network access over HTTPS to compromise the service by performing unauthorized data modification operations such as update, insert, or delete. The CVSS 3.1 base score is 5.3, reflecting a medium severity primarily due to integrity impact without confidentiality or availability impact. Oracle has addressed this vulnerability in its May 2026 Critical Security Patch Update, which includes 35 security patches across multiple products including Oracle REST Data Services. The vendor advisory emphasizes the importance of applying these patches without delay and offers guidance on temporary risk reduction measures such as blocking network protocols or removing unnecessary privileges, though these are not long-term solutions.
Potential Impact
Successful exploitation allows unauthorized modification of some accessible data in Oracle REST Data Services, impacting data integrity. There is no impact on confidentiality or availability according to the CVSS vector. No known exploits have been reported in the wild. The vulnerability can be exploited remotely without authentication over HTTPS.
Mitigation Recommendations
Oracle has released patches for this vulnerability as part of the May 2026 Critical Security Patch Update. Customers are strongly advised to apply these security patches as soon as possible to remediate the vulnerability. Until patches are applied, risk may be partially reduced by blocking network protocols required for the attack or by removing unnecessary privileges from users, but these are not substitutes for patching. Oracle recommends testing any such mitigations in non-production environments before deployment. Staying on supported product versions and promptly applying security updates is critical to maintaining security.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- oracle
- Date Reserved
- 2026-05-18T15:55:10.305Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://www.oracle.com/security-alerts/cspumay2026.html","vendor":"Oracle"}]
Threat ID: 6a18aa30e29bf47b5027becd
Added to database: 5/28/2026, 8:48:48 PM
Last enriched: 5/28/2026, 9:19:47 PM
Last updated: 5/29/2026, 8:17:55 AM
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.