PatchSiren cyber security CVE debrief
CVE-2026-35277 Oracle Corporation CVE debrief
A high-severity vulnerability in Oracle REST Data Services (ORDS) Core component affects versions 24.2.0 through 26.1.0. Published 2026-05-28, this flaw allows low-privileged attackers with network access via HTTPS to compromise ORDS, potentially resulting in unauthorized creation, deletion, or modification of critical data as well as unauthorized access to all ORDS-accessible data. The CVSS 3.1 score of 8.1 reflects high impacts to confidentiality and integrity with no availability impact. Attack complexity is low, requiring no user interaction. Oracle has addressed this in their May 2026 Critical Patch Update.
- Vendor
- Oracle Corporation
- Product
- Oracle REST Data Services
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-28
- Original CVE updated
- 2026-06-03
- Advisory published
- 2026-05-28
- Advisory updated
- 2026-06-03
Who should care
Organizations running Oracle REST Data Services 24.2.0-26.1.0, particularly those exposing ORDS to external networks or hosting sensitive data. Database administrators, security teams, and compliance officers responsible for Oracle application security should prioritize patching.
Technical summary
Oracle REST Data Services Core component in versions 24.2.0-26.1.0 fails to properly validate or authorize requests from low-privileged users over HTTPS. The vulnerability enables network-based attackers to escalate privileges indirectly through data manipulation, achieving unauthorized read/write access to all ORDS-managed data. No availability impact is associated with this flaw. The attack requires authenticated but low-privileged access, making insider threats and compromised credential scenarios particularly relevant.
Defensive priority
HIGH
Recommended defensive actions
- Apply Oracle Critical Patch Update for May 2026 immediately to affected ORDS installations
- Upgrade Oracle REST Data Services to a patched version beyond 26.1.0
- Review ORDS deployment access controls and restrict network exposure where possible
- Audit ORDS-accessible data for signs of unauthorized access or modification
- Monitor HTTPS access logs for anomalous activity from low-privileged accounts
Evidence notes
CVE published 2026-05-28T21:16:29.460Z. CVSS 3.1: 8.1 (High). Attack vector: network, low complexity, low privileges required, no user interaction. Confidentiality and Integrity impacts rated HIGH; Availability impact NONE. Oracle security alert reference provided.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-35277 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-35277
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-35277 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-35277
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cspumay2026.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.