Unauth RCE in ORDS Mongoapi 24.2.026.1.0 (Denial of Service)
CVE-2026-46829 Published on May 28, 2026
Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle REST Data Services. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Vulnerability Analysis
CVE-2026-46829 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a high impact on availability.
Products Associated with CVE-2026-46829
Want to know whenever a new CVE is published for Oracle Rest Data Services? stack.watch will email you.
Affected Versions
Oracle Corporation Oracle REST Data Services:- Version 24.2.0, <= 26.1.0 is affected.