Oracle REST Data Services Core 24.2.0-26.1.0: Unauth HTTPS DOS
CVE-2026-46843 Published on May 28, 2026
Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle REST Data Services. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Vulnerability Analysis
CVE-2026-46843 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a small impact on availability.
Products Associated with CVE-2026-46843
Want to know whenever a new CVE is published for Oracle Rest Data Services? stack.watch will email you.
Affected Versions
Oracle Corporation Oracle REST Data Services:- Version 24.2.0, <= 26.1.0 is affected.