DNA View

High Severity Vulnerability

This vulnerability has been rated as High severity. Immediate action is recommended.

CVE-2026-21973

High
Low Medium High Critical
8.1
CVSS Score
Published: Jan 20, 2026
Last Modified: Feb 02, 2026

Vulnerability Description

Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: Security Management System). Supported versions that are affected are 14.5.0.15.0, 14.7.0.8.0 and 14.8.0.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle FLEXCUBE Investor Servicing accessible data as well as unauthorized access to critical data or complete access to all Oracle FLEXCUBE Investor Servicing accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

CVSS Metrics

Common Vulnerability Scoring System

Vector String:

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
N
Attack Complexity
L
Privileges Required
L
User Interaction
N
Scope
U
Confidentiality
H
Integrity
H
Availability
N

Known Affected Software

3 configuration(s) from 1 vendor(s)

flexcube_investor_servicing
Version:
14.5.0.15.0
CPE:
cpe:2.3:a:oracle:flexcube_investor_servicing:14.5.0.15.0:*:*:*:*:*:*:*
flexcube_investor_servicing
Version:
14.8.0.1.0
CPE:
cpe:2.3:a:oracle:flexcube_investor_servicing:14.8.0.1.0:*:*:*:*:*:*:*
flexcube_investor_servicing
Version:
14.7.0.8.0
CPE:
cpe:2.3:a:oracle:flexcube_investor_servicing:14.7.0.8.0:*:*:*:*:*:*:*
This vulnerability affects 3 software configuration(s). Ensure you patch all affected systems.

Available Security Patches

1 patch available from vendors

View All Patches
Oracle

CPUJAN2026

Oracle Critical Patch Update Advisory - January 2026

Severity
Critical
Released
Jan 20, 2026
Restart Required
Security Update

Severity Details

8.1
out of 10.0
High

Weakness Type (CWE)

NVD-CWE-noinfo

Key Information

Published Date
January 20, 2026