OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-15638

CRITICAL · CVSS 9.1 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-09-16 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

An unauthenticated user with access to Oracle's Secret Server can exploit a padding oracle vulnerability to decrypt or encrypt sensitive data using the server's cryptographic keys, although the keys themselves remain undisclosed. This critical flaw poses a significant risk to data confidentiality and integrity, making it essential for organizations utilizing Oracle Secret Server to prioritize immediate remediation efforts.

CVE
CVE-2026-15638
Severity
CRITICAL
CVSS
9.1
EPSS
0.20%
Oracle

Original NVD Description

An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys. The key itself is not exposed.