CVE-2026-21997 is a vulnerability in Oracle Life Sciences Empirica Signal (versions 9.2.1-9.2.3), a component of Oracle Life Science Applications. The flaw enables low-privileged attackers with network access to compromise the product and potentially impact other connected systems through scope changes. The vulnerability carries a CVSS 3.1 score of 8.5 (HIGH) and can be exploited remotely over HTTP with low complexity and no user interaction required. Successful exploitation allows attackers to create, delete, or modify critical data within Empirica Signal and read unauthorized subsets of accessible data, presenting significant integrity and confidentiality risks. Current exploitation status indicates minimal public attention and no active exploitation in the wild. The EPSS score of 0.00025 suggests the vulnerability ranks lower than 99.93% of all known CVEs in terms of exploitation probability, and it does not appear on the CISA Known Exploited Vulnerabilities list, indicating no evidence of active weaponization at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.2.1, <= 9.2.3CPE matchmatch criteria | cpe:2.3:a:oracle:life_sciences_empirica_signal:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.