PatchSiren cyber security CVE debrief
CVE-2026-46830 Oracle Corporation CVE debrief
Oracle REST Data Services (ORDS) versions 24.2.0 through 26.1.0 contain an unauthenticated information disclosure vulnerability in the MongoAPI component. The flaw allows remote attackers with network access via HTTPS to obtain unauthorized read access to a subset of ORDS-accessible data without authentication. The vulnerability is rated CVSS 3.1 Base Score 5.3 (Medium severity) with a vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N, indicating network attack vector, low attack complexity, no privileges required, no user interaction, and low confidentiality impact with no integrity or availability effects. The vulnerability was disclosed by Oracle in their May 2026 Critical Patch Update security advisory. No known exploitation in the wild or ransomware campaign use has been reported. Organizations should apply Oracle's May 2026 CPU patches and restrict network access to ORDS MongoAPI endpoints where patching is not immediately feasible.
- Vendor
- Oracle Corporation
- Product
- Oracle REST Data Services
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-28
- Original CVE updated
- 2026-05-29
- Advisory published
- 2026-05-28
- Advisory updated
- 2026-05-29
Who should care
Organizations running Oracle REST Data Services versions 24.2.0 through 26.1.0 with MongoAPI enabled, particularly those exposing ORDS endpoints to untrusted networks.
Technical summary
Unauthenticated information disclosure in Oracle REST Data Services MongoAPI component (versions 24.2.0-26.1.0) allowing remote attackers to read subset of accessible data via HTTPS. CVSS 3.1: 5.3 (Medium).
Defensive priority
medium
Recommended defensive actions
- Apply Oracle May 2026 Critical Patch Update patches for Oracle REST Data Services
- Review and restrict network access to ORDS MongoAPI endpoints
- Monitor Oracle security alerts for additional guidance
- Verify ORDS version and upgrade to patched release if running affected versions 24.2.0-26.1.0
Evidence notes
Vulnerability affects ORDS MongoAPI component in versions 24.2.0-26.1.0. CVSS 3.1 score 5.3 (Medium). Unauthenticated HTTPS-based exploitation possible.
Official resources
-
CVE-2026-46830 CVE record
CVE.org
-
CVE-2026-46830 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
Oracle disclosed this vulnerability in their May 2026 Critical Patch Update security advisory.