By vendor

Oracle vulnerabilities

Known CVEs affecting Oracle products, prioritized by severity, with SEC.co remediation and detection guidance.

111 published vulnerabilities · page 2 of 2

  • CVE-2026-46877MEDIUM 6.0

    A vulnerability in Oracle VM VirtualBox version 7.2.8 allows an administrator or highly privileged user on the host system to read sensitive data from the virtual machine. The flaw is in the VMSVGA graphics device component. An attacker would need administrative-level access to the infrastructure running VirtualBox, but from that position can extract confidential information that VirtualBox can access. The vulnerability does not enable attackers to modify or delete data, nor does it crash the system.

  • CVE-2026-46790MEDIUM 5.3

    Oracle WebCenter Content version 14.1.2.0.0 contains an information disclosure vulnerability that allows an unauthenticated attacker to read sensitive data over the network without requiring credentials or user interaction. The vulnerability is exposed through HTTP and rated medium severity due to its limited scope—only confidentiality is affected, with no impact to data integrity or system availability.

  • CVE-2026-46830MEDIUM 5.3

    Oracle REST Data Services contains an information disclosure vulnerability in its Mongoapi component that allows an unauthenticated attacker to read sensitive data over the network without authentication. An attacker with network access can exploit this flaw via HTTPS to gain unauthorized visibility into data normally protected by REST Data Services, though they cannot modify or delete information. The vulnerability affects versions 24.2.0 through 26.1.0 and requires no special conditions—it's straightforward to trigger.

  • CVE-2026-46841MEDIUM 5.3

    Oracle REST Data Services versions 24.2.0 through 26.1.0 contain a network-accessible vulnerability that allows unauthenticated attackers to read sensitive data. An attacker on the network can reach the service over HTTPS without credentials and gain unauthorized access to a subset of the data REST Data Services manages. This is not a critical vulnerability—it does not enable system takeover, data modification, or service disruption—but it does represent a meaningful confidentiality risk for organizations relying on REST Data Services for data access control.

  • CVE-2026-46842MEDIUM 5.3

    Oracle REST Data Services versions 24.2.0 through 26.1.0 contain a vulnerability that allows an unauthenticated attacker to modify, add, or delete data accessible through the service over the network. The vulnerability requires no special conditions to exploit and can be triggered via standard HTTPS connections. While an attacker cannot read data or crash the service, they can alter stored information, which poses a direct integrity risk to applications relying on ORDS for data access.

  • CVE-2026-46843MEDIUM 5.3

    Oracle REST Data Services versions 24.2.0 through 26.1.0 contain a vulnerability that allows an attacker without credentials to trigger a partial denial of service over the network via HTTPS. The vulnerability is in the Core component and requires no special user interaction. An attacker can exploit this remotely to degrade availability of the REST Data Services instance, though data confidentiality and integrity are not at risk.

  • CVE-2026-46772MEDIUM 4.7

    Oracle's Application Development Framework (ADF), a core component of Fusion Middleware, contains a privilege-escalation vulnerability affecting versions 12.2.1.4.0 and 14.1.2.0.0. An attacker with high-level administrative access and direct infrastructure access could exploit insufficient privilege controls to read sensitive application data or modify certain records. The attack is not trivial—it requires both elevated credentials and specific configuration conditions—but poses meaningful risk to organizations running vulnerable ADF instances, particularly those handling sensitive business data through ADF-based applications.

  • CVE-2026-46771MEDIUM 4.1

    CVE-2026-46771 is a localized privilege-escalation vulnerability in Oracle Application Development Framework (ADF) that allows a highly privileged attacker already logged into the infrastructure to access sensitive application data. The attacker must be an administrative user on the machine running ADF, and even then exploiting it requires specific conditions to be met. The primary risk is unauthorized disclosure of data within ADF systems—the vulnerability does not enable attackers to modify or delete data, nor does it allow takeover of the ADF service itself.

  • CVE-2026-46815LOW 3.2

    CVE-2026-46815 is a low-severity information disclosure flaw in Oracle VM VirtualBox 7.2.8 affecting the VMSVGA graphics device driver. A high-privilege user already logged into a system running VirtualBox can read a limited subset of VirtualBox data that should not be accessible to them. The vulnerability does not enable attackers to modify data, crash the application, or gain system-level control. Its scope extends beyond VirtualBox itself—successful exploitation could indirectly expose data relevant to other products running on or managed by the affected host.

  • CVE-2026-46816LOW 3.2

    CVE-2026-46816 is a low-severity information disclosure vulnerability affecting Oracle VM VirtualBox 7.2.8. A high-privileged user already logged into the host system running VirtualBox can read a limited subset of data accessible to VirtualBox. The attack requires existing local access with administrative-level privileges and occurs through the VMSVGA device component. Because VirtualBox often runs on infrastructure managing multiple virtual machines, successful exploitation could expose sensitive data across guest systems, though the scope of readable data is restricted.

  • CVE-2026-46874LOW 3.2

    Oracle VM VirtualBox version 7.2.8 contains a privilege escalation vulnerability affecting the Core component. An attacker with high-level privileges and local access to the system running VirtualBox can read sensitive data that VirtualBox manages or processes. While the vulnerability itself resides in VirtualBox, successful exploitation could expose information relevant to other systems or virtual machines it hosts, expanding the security footprint beyond VirtualBox alone. The vulnerability requires the attacker to already have administrative or high-privilege access to the infrastructure, which significantly limits the practical attack surface in most environments.