VDB

CVE-2026-21973

CVE-2026-21973 PUBLISHED CVSS 8.100000381469727 HIGH

Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: Security Management System). Supported versions that are affected are 14.5.0.15.0, 14.7.0.8.0 and 14.8.0.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle FLEXCUBE Investor Servicing accessible data as well as unauthorized access to critical data or complete access to all Oracle FLEXCUBE Investor Servicing accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

EPSS 0.12% · 30.6th percentile

Risk Scores

CVSS v3.1
8.100000381469727
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS Score
0.12%
30.6th percentile

Affected Products

VendorProductVersions
oracleflexcube_investor_servicing14.8.0.1.0, 14.7.0.8.0, 14.5.0.15.0
Oracle CorporationOracle FLEXCUBE Investor Servicing14.5.0.15.0, 14.7.0.8.0, 14.8.0.1.0

Timeline

  • Jan 20, 2026 CVE Published
  • Jan 20, 2026 PoC Published
  • Jan 20, 2026 PoC Published
  • Jan 21, 2026 EPSS Score
  • Jan 21, 2026 PoC Published
  • Jan 21, 2026 CVE Updated
  • Jan 21, 2026 PoC Published
  • Jan 24, 2026 EPSS Score
  • Jan 26, 2026 EPSS Score
  • Jan 29, 2026 EPSS Score
  • Feb 1, 2026 EPSS Score
  • Feb 3, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›