PatchSiren cyber security CVE debrief
CVE-2026-46830 Oracle Corporation CVE debrief
Oracle REST Data Services (ORDS) versions 24.2.0 through 26.1.0 contain an unauthenticated information disclosure vulnerability in the MongoAPI component. The flaw allows remote attackers with network access via HTTPS to obtain unauthorized read access to a subset of ORDS-accessible data without authentication. The vulnerability is rated CVSS 3.1 Base Score 5.3 (Medium severity) with a vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N, indicating network attack vector, low attack complexity, no privileges required, no user interaction, and low confidentiality impact with no integrity or availability effects. The vulnerability was disclosed by Oracle in their May 2026 Critical Patch Update security advisory. No known exploitation in the wild or ransomware campaign use has been reported. Organizations should apply Oracle's May 2026 CPU patches and restrict network access to ORDS MongoAPI endpoints where patching is not immediately feasible.
- Vendor
- Oracle Corporation
- Product
- Oracle REST Data Services
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-28
- Original CVE updated
- 2026-07-21
- Advisory published
- 2026-05-28
- Advisory updated
- 2026-07-21
Who should care
Organizations running Oracle REST Data Services versions 24.2.0 through 26.1.0 with MongoAPI enabled, particularly those exposing ORDS endpoints to untrusted networks.
Technical summary
Unauthenticated information disclosure in Oracle REST Data Services MongoAPI component (versions 24.2.0-26.1.0) allowing remote attackers to read subset of accessible data via HTTPS. CVSS 3.1: 5.3 (Medium).
Defensive priority
medium
Recommended defensive actions
- Apply Oracle May 2026 Critical Patch Update patches for Oracle REST Data Services
- Review and restrict network access to ORDS MongoAPI endpoints
- Monitor Oracle security alerts for additional guidance
- Verify ORDS version and upgrade to patched release if running affected versions 24.2.0-26.1.0
Evidence notes
Vulnerability affects ORDS MongoAPI component in versions 24.2.0-26.1.0. CVSS 3.1 score 5.3 (Medium). Unauthenticated HTTPS-based exploitation possible.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-46830 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-46830
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-46830 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46830
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cspumay2026.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.