CVE-2026-35229 is a vulnerability in the Java VM component of Oracle Database Server affecting versions 19.3-19.30 and 21.3-21.21. The flaw allows unauthenticated attackers with network access via Oracle Net to compromise the Java VM and gain unauthorized access to sensitive data or complete access to all Java VM accessible information. The vulnerability carries a CVSS 3.1 score of 7.5 (HIGH), with the attack vector being network-based, requiring low complexity and no user interaction or authentication. Exploitation would result in high-impact confidentiality breaches with no integrity or availability impacts. Currently, this vulnerability shows minimal exploitation activity with an EPSS score of 0.00032, indicating it is not actively exploited in the wild, has not been added to CISA's Known Exploited Vulnerabilities catalog, and remains inactive on threat intelligence hot lists.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 19.3, <= 19.30CPE matchmatch criteria | cpe:2.3:a:oracle:java_virtual_machine:*:*:*:*:*:*:*:* | ||
>= 21.3, <= 21.21CPE matchmatch criteria | cpe:2.3:a:oracle:java_virtual_machine:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.