CVE-2026-21972
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-21972 is an information disclosure vulnerability in the Oracle Configurator product of Oracle E-Business Suite, specifically affecting the User Interface component. It impacts supported versions 12.2.3 through 12.2.15. The vulnerability allows unauthenticated attackers with network access via HTTP to gain unauthorized read access to a subset of Oracle Configurator accessible data. It was published on January 20, 2026, and addressed in Oracle's January 2026 Critical Patch Update. It carries a CVSS v3.1 base score of 5.3 (Medium) (Oracle CPU Jan 2026, Red Hat CVE).

Technical details

The vulnerability resides in the User Interface component of Oracle Configurator and is classified as an information disclosure flaw. It is easily exploitable with no authentication, no user interaction, and low attack complexity required — an attacker only needs network access via HTTP. The root cause is not publicly detailed by Oracle, which follows its standard policy of not disclosing granular vulnerability analysis; however, the attack vector and impact pattern are consistent with improper access control or insufficient authorization checks on UI endpoints (CWE-284 or similar). No public technical write-ups or proof-of-concept code have been identified (Oracle CPU Jan 2026).

Impact

Successful exploitation results in unauthorized read access to a subset of data accessible within Oracle Configurator, impacting confidentiality only — there is no impact to system integrity or availability. The exposed data may include configuration data, product rules, or other business-sensitive information managed within the Oracle E-Business Suite environment. Lateral movement potential is limited given the read-only nature of the vulnerability, but exposed data could aid further reconnaissance or targeted attacks against the broader E-Business Suite deployment (Oracle CPU Jan 2026).

Exploitability

There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation as of the time of reporting. The EPSS score is approximately 0.028% (0.000280), indicating a very low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified (Red Hat CVE).

Mitigation and workarounds

Oracle has released patches for this vulnerability as part of the January 2026 Critical Patch Update (CPU), applicable to Oracle Configurator versions 12.2.3 through 12.2.15. Organizations should apply the CPU patches immediately to all affected instances. As a temporary measure, Oracle recommends blocking network protocols required by the attack (HTTP access to Oracle Configurator) at the network level, and restricting access to trusted networks and users only. Implementing web application firewall (WAF) rules to detect anomalous HTTP requests to Oracle Configurator endpoints is also advisable until patching is complete (Oracle CPU Jan 2026).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management