Critical Security Vulnerabilities in Oracle REST Data Services (ORDS) – May 2026

Since the security of your systems and data is a priority for us, we would like to inform you about the details and recommended steps.
Which versions are affected?
The vulnerabilities affect ORDS versions from 24.2.0 to 26.1.0.
Overview of the most severe risks
A total of 11 vulnerabilities were identified in the system, several of which have critical severity scores (CVSS):
- Complete takeover of ORDS (CVSS 10.0 and 9.9):
- CVE-2026-46840 (score 10.0): A very easily exploitable vulnerability in the Backend-as-a-Service component that allows an unauthenticated attacker to completely take over ORDS over the network (HTTPS).
- CVE-2026-46775 and CVE-2026-46839 (score 9.9): Allow an attacker with low privileges to fully take control of ORDS, with a significant impact on related products.
- Critical data access and modification (CVSS 9.1 and 8.1):
- CVE-2026-2332 (score 9.1): An unauthenticated attacker can gain unauthorized access to read, create, modify, or delete all critical data accessible through ORDS (vulnerability in the Eclipse Jetty component).
- Other risks: Other flaws can cause a complete Denial of Service (DoS), or unauthorized reading or modification of smaller portions of data.
- What does this mean for you?
If you are using an affected version of ORDS and your environment is accessible over the network, attackers could exploit these vulnerabilities without needing sophisticated tools or high-level access privileges. In the worst-case scenario, there is a risk of leakage or damage to company data and service outages.
Recommended solution
Oracle has already released patches that fix these security gaps. We strongly recommend updating ORDS to the latest secure version.
How we can help you
Our team is ready to analyze your current environment, verify the exact ORDS version, and plan a safe deployment of the patches at a time that minimally affects your operations.
Please reply to this email or contact your dedicated administrator so we can arrange the next steps.





