← All Advisories

CVE-2026-22010

Status: UPDATED  |  Advisory ID: CVE-2026-22010

Key Details

CVECVE-2026-22010
CVSSCVSS 7.5 (High).
Affected productsOracle financial_services_analytical_applications_infrastructure
Classified asCWE-284 (Improper Access Control)

What to Know

Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-22010
Vendor advisoryhttps://www.oracle.com/security-alerts/cpuapr2026.html