#VU121708 Improper input validation in Oracle Zero Data Loss Recovery Appliance Software - CVE-2026-21977
Published: January 20, 2026
Oracle Zero Data Loss Recovery Appliance Software
Oracle
Description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
The vulnerability exists due to improper input validation within the Security component in Oracle Zero Data Loss Recovery Appliance Software. A remote non-authenticated attacker can exploit this vulnerability to gain access to sensitive information.