Back to CVE List

CVE-2026-35255

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
6.6 / 10
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

Vulnerability Description

Vulnerability in the Oracle Cloud Native Environment Command Line Interface product of Oracle Open Source Projects. The supported versions that is affected is v2.3.2. Easily exploitable vulnerability allows unauthenticated attacker to compromise Oracle Cloud Native Environment Command Line Interface product via a malicious environment variable. Successful attacks of this vulnerability can result in Oracle Cloud Native Environment Command Line Interface allowing users to execute arbitrary code.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-94
Source
NVD
Vendor
Oracle Corporation
Product
Oracle Cloud Native Environment Command Line Interface

External References

Discussion (0)

Add Comment

No comments yet. Be the first!