CVE-2026-21994Disclosure(oracle / okit)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Prioritize remediation for oracle okit systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Vulnerability in the Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit product of Oracle Open Source Projects (component: Desktop). The supported version that is affected is 0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit. Successful attacks of this vulnerability can result in takeover of Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • okit

Threat summary

  • Public PoC and exploit tooling are both present
  • 9 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • General: 3 classified signals
  • Peaked 1d ago at 4 mentions (2026-03-18); latest day: 2
  • 9 total mentions across 3 days

Affected systems

Vendors
Products
okit

1 version affected across 1 product

Deep dive

Activity timeline9 mentions / 3d
01234Mentions · 2026-03-17: 3Mentions · 2026-03-18: 4Mentions · 2026-03-20: 2PoC Mentioned / Linked · 2026-03-20: 1Exploit Tool / Code · 2026-03-20: 1Technical Details · 2026-03-17: 1Technical Details · 2026-03-18: 2Technical Details · 2026-03-20: 203-1703-1803-20
Signal classification3 categories
Disclosure
555.6%
General
333.3%
PoC
111.1%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-03-173
Disclosure1General2
2026-03-184
Disclosure3General1
2026-03-202
Disclosure1PoC1
Full discourse9 posts
  • Gray Hats@the_yellow_fall
    Disclosure

    A critical 9.8 CVSS flaw (CVE-2026-21994) in Oracle's Edge Cloud Infrastructure Toolkit allows unauthenticated remote attackers a total takeover. #OracleCloud #CVE #CyberSecurity #CloudSecurity #InfoSec #CVSS #Vulnerability #ThreatIntel #EdgeComputing https://securityonline.info/edge-disaster-critical-9-8-cvss-flaw-oracle-cloud-infrastructure-toolkit-takeover/ https://t.co/6p0ewYWMAH

    Post summary

    The tweet announces a new Oracle Edge Cloud Infrastructure Toolkit vulnerability (CVE‑2026‑21994) with a critical 9.8 CVSS score that permits unauthenticated remote attackers to take over the system.

    02010436
    10.7K followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🔴 CVE-2026-21994 - Critical Vulnerability in the Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit product of Oracle Open Source Projects (component: Desktop). The supported version that is affec... https://www.thehackerwire.com/vulnerability/CVE-2026-21994/ https://t.co/qa9fg5nnws

    Post summary

    The text merely announces a critical Oracle vulnerability without providing exploitation details, patches, or evidence of active use.

    0001073
    138 followersView on X
  • Omote-Ura@nyakojiru
    PoC

    https://www.thehackerwire.com/oracle-edge-cloud-infrastructure-designer-critical-takeover-cve-2026-21994/

    Post summary

    The HackerWire article announces Oracle Edge Cloud Infrastructure Designer CVE‑2026‑21994, provides a working exploit code that achieves full takeover, and highlights the urgency given the absence of an available patch.

    0000022
    127 followersView on X
  • Gouri Sankar A@g0w6y
    Disclosure

    Discovered vuln CVE-2026-21994 assigned & credited by @Oracle ! 9.8 Critical in Oracle Edge Cloud Infrastructure Designer Toolkit (v0.3.0 Desktop). Unauth remote HTTP takeover. Credit: Gouri Sankar A https://www.oracle.com/security-alerts/all-oracle-cves-outside-other-oracle-public-documents.html NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-21994 https://t.co/tUBhUwXlKk

    Post summary

    The tweet announces CVE-2026-21994 as a critical unauthenticated remote HTTP takeover vulnerability in Oracle Edge Cloud Infrastructure Designer Toolkit, with no PoC, exploit code, or patch details provided.

    0000059
    5 followersView on X
  • dbugs@ptdbugs
    Disclosure

    CVE: CVE-2026-21994 Vendor: Oracle corporation Product: Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit CVSS: 9.8 Credits: n/a Description: Vulnerability in the Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit product of Oracle Open Source Projects (component: Desktop). The supported version that is affected is 0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit. Successful attacks of this vulnerability can result in takeover of Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-21994 • https://www.oracle.com/security-alerts/public-vuln-to-advisory-mapping.html #dbugs_vuln

    Post summary

    The text provides a formal disclosure of a high‑severity vulnerability in Oracle Edge Cloud Infrastructure Designer, detailing its technical aspects but offering no PoC, exploit code, or patch information.

    00000105
    633 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-21994 Vulnerability in the Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit product of Oracle Open Source Projects (component: Desktop). The supported … https://www.cve.org/CVERecord?id=CVE-2026-21994

    Post summary

    The text provides a CVE identifier and product association, linking to the official CVE record but offering no further technical, exploit, or mitigation details.

    00000155
    56.7K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in Oracle Edge Cloud Infrastructure Designer (CVE-2026-21994) https://vuldb.com/?id.351396

    Post summary

    A new high‑criticality vulnerability (CVE‑2026‑21994) has been disclosed for Oracle Edge Cloud Infrastructure Designer, as referenced by a VulDB entry.

    0000091
    2.1K followersView on X
  • CVEFind.com@CveFindCom
    General

    [CVE-2026-21994: CRITICAL] Critical vulnerability discovered in Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit (Desktop component). Easy exploitation enables unauthorized remote access w...#cve,CVE-2026-21994,#cybersecurity https://cvefind.com/CVE-2026-21994

    Post summary

    The post announces a critical vulnerability in Oracle Edge Cloud Infrastructure Designer that enables remote access, but it offers no concrete technical details, fixes, or evidence of exploitation.

    0000072
    603 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-21994: Ora... Oracle's Edge Cloud toolkit serves up complete system takeover via HTTP with zero auth required - CVSS 9.8 screams "patch immediately" #Oracle #RCE. https://zerodaysignal.com/vulnerability/CVE-2026-21994 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A new, high‑severity Oracle Edge Cloud toolkit vulnerability (CVE‑2026‑21994) permits complete system takeover via unauthenticated HTTP requests, urging immediate patching.

    00000105
    155 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apporacleokit0.3.0--

Explore more