CVE-2026-35255: Code Injection
Vulnerability in the Oracle Cloud Native Environment Command Line Interface product of Oracle Open Source Projects. The supported versions that is affected is v2.3.2. Easily exploitable vulnerability allows unauthenticated attacker to compromise Oracle Cloud Native Environment Command Line Interface product via a malicious environment variable. Successful attacks of this vulnerability can result in Oracle Cloud Native Environment Command Line Interface allowing users to execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35255?
CVE-2026-35255 is rated as easily exploitable, allowing unauthenticated attackers to compromise the affected system.
How do I fix CVE-2026-35255?
To fix CVE-2026-35255, upgrade the Oracle Cloud Native Environment Command Line Interface to a patched version beyond 2.3.2.
What software is affected by CVE-2026-35255?
CVE-2026-35255 affects version 2.3.2 of the Oracle Cloud Native Environment Command Line Interface.
Can CVE-2026-35255 be exploited remotely?
Yes, CVE-2026-35255 can be exploited remotely by an unauthenticated attacker.
Is there a workaround for CVE-2026-35255?
Currently, there are no official workarounds available for CVE-2026-35255; upgrading to a secure version is recommended.