← All Advisories

Oracle Life Sciences Empirica Signal Access Control Weakness Scores 8.5

Last refreshed2026-09-26

Status: UPDATED  |  Advisory ID: CVE-2026-21997

Key Details

CVECVE-2026-21997
CVSS Score / Version8.5 (High) / CVSS v3.1
Updated2026-09-24
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is changed; confidentiality impact is low; integrity impact is high; availability impact is none.
Affected productsOracle Life Sciences Empirica Signal
Classified asCWE-284 (Improper Access Control)
Exploitation prediction (EPSS)0.20% probability of exploitation in the next 30 days (9% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
OracleLife Sciences Empirica Signal
SubsystemsGeneral OT
SectorsMultiple

What to Know

Vulnerability in the Oracle Life Sciences Empirica Signal product of Oracle Life Science Applications (component: Common Core). Supported versions that are affected are 9.2.1-9.2.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Life Sciences Empirica Signal. While the vulnerability is in Oracle Life Sciences Empirica Signal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Life Sciences Empirica Signal accessible data as well as unauthorized read access to a subset of Oracle Life Sciences Empirica Signal accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N).

What to Do

Monitor Oracle's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-21997
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-21997
Vendor advisoryhttps://www.oracle.com/security-alerts/cpuapr2026.html