September 7, 2026

CVE Watchtower


← Back to CVE List

CVE-2026-23927NVD

Vulnerability Summary

A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an attacker-controlled server and leaking Oracle database credentials if they are saved in a named session.
Severity Level
UNKNOWN
Published Date
May 6, 2026
Last Modified
May 6, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.05%Probability
Root Weakness (CWE)
N/A