Loading market data...
← Back to CVE feed

CVE-2026-35254

MEDIUM CVSS 6.1 View on NVD ↗

Description

Vulnerability in the Oracle OCI CLI product of Oracle Open Source Projects. The supported versions that is affected is 3.77. Easily exploitable vulnerability allows unauthenticated attacker with network access to compromise Oracle OCI CLI. Successful attacks of this vulnerability can result in Oracle OCI CLI allowing users to place imported files outside the intended directory.

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L

Affected Products

oracle/cloud_infrastructure_cli
Published: May 06, 2026 08:16 UTC Modified: May 06, 2026 20:30 UTC