PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-46830 Oracle Corporation CVE debrief

Oracle REST Data Services (ORDS) versions 24.2.0 through 26.1.0 contain an unauthenticated information disclosure vulnerability in the MongoAPI component. The flaw allows remote attackers with network access via HTTPS to obtain unauthorized read access to a subset of ORDS-accessible data without authentication. The vulnerability is rated CVSS 3.1 Base Score 5.3 (Medium severity) with a vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N, indicating network attack vector, low attack complexity, no privileges required, no user interaction, and low confidentiality impact with no integrity or availability effects. The vulnerability was disclosed by Oracle in their May 2026 Critical Patch Update security advisory. No known exploitation in the wild or ransomware campaign use has been reported. Organizations should apply Oracle's May 2026 CPU patches and restrict network access to ORDS MongoAPI endpoints where patching is not immediately feasible.

Vendor
Oracle Corporation
Product
Oracle REST Data Services
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-28
Original CVE updated
2026-07-21
Advisory published
2026-05-28
Advisory updated
2026-07-21

Who should care

Organizations running Oracle REST Data Services versions 24.2.0 through 26.1.0 with MongoAPI enabled, particularly those exposing ORDS endpoints to untrusted networks.

Technical summary

Unauthenticated information disclosure in Oracle REST Data Services MongoAPI component (versions 24.2.0-26.1.0) allowing remote attackers to read subset of accessible data via HTTPS. CVSS 3.1: 5.3 (Medium).

Defensive priority

medium

Recommended defensive actions

  • Apply Oracle May 2026 Critical Patch Update patches for Oracle REST Data Services
  • Review and restrict network access to ORDS MongoAPI endpoints
  • Monitor Oracle security alerts for additional guidance
  • Verify ORDS version and upgrade to patched release if running affected versions 24.2.0-26.1.0

Evidence notes

Vulnerability affects ORDS MongoAPI component in versions 24.2.0-26.1.0. CVSS 3.1 score 5.3 (Medium). Unauthenticated HTTPS-based exploitation possible.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-46830 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-46830

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-46830 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46830

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.