Report: Essential Guide: CVE-2026-23927 - Agent 2 Oracle plugin TNS connection string injection via the 'service' parameter

Report: Essential Guide: CVE-2026-23927 - Agent 2 Oracle plugin TNS connection string injection via the 'service' parameter

CVE ID :CVE-2026-23927 Published : May 6, 2026, 6:59 a.m. | 1 hour, 31 minutes ago Description :A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an attacker-controlled server and leaking Oracle database credentials if they are saved in a named session. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
May 6, 2026
Affected Product: Oracle TNS