PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-46830 Oracle Corporation CVE debrief

Oracle REST Data Services (ORDS) versions 24.2.0 through 26.1.0 contain an unauthenticated information disclosure vulnerability in the MongoAPI component. The flaw allows remote attackers with network access via HTTPS to obtain unauthorized read access to a subset of ORDS-accessible data without authentication. The vulnerability is rated CVSS 3.1 Base Score 5.3 (Medium severity) with a vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N, indicating network attack vector, low attack complexity, no privileges required, no user interaction, and low confidentiality impact with no integrity or availability effects. The vulnerability was disclosed by Oracle in their May 2026 Critical Patch Update security advisory. No known exploitation in the wild or ransomware campaign use has been reported. Organizations should apply Oracle's May 2026 CPU patches and restrict network access to ORDS MongoAPI endpoints where patching is not immediately feasible.

Vendor
Oracle Corporation
Product
Oracle REST Data Services
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-28
Original CVE updated
2026-05-29
Advisory published
2026-05-28
Advisory updated
2026-05-29

Who should care

Organizations running Oracle REST Data Services versions 24.2.0 through 26.1.0 with MongoAPI enabled, particularly those exposing ORDS endpoints to untrusted networks.

Technical summary

Unauthenticated information disclosure in Oracle REST Data Services MongoAPI component (versions 24.2.0-26.1.0) allowing remote attackers to read subset of accessible data via HTTPS. CVSS 3.1: 5.3 (Medium).

Defensive priority

medium

Recommended defensive actions

  • Apply Oracle May 2026 Critical Patch Update patches for Oracle REST Data Services
  • Review and restrict network access to ORDS MongoAPI endpoints
  • Monitor Oracle security alerts for additional guidance
  • Verify ORDS version and upgrade to patched release if running affected versions 24.2.0-26.1.0

Evidence notes

Vulnerability affects ORDS MongoAPI component in versions 24.2.0-26.1.0. CVSS 3.1 score 5.3 (Medium). Unauthenticated HTTPS-based exploitation possible.

Official resources

Oracle disclosed this vulnerability in their May 2026 Critical Patch Update security advisory.