logo

Oracle Fixes Critical Bug in Cloud Code Editor

ID: f90c8a80-1401-5054-8c80-0ee59429d11c

STIX ID: report--f90c8a80-1401-5054-8c80-0ee59429d11c

Feed Name: Dark Reading

Threat Score
65/100

Date Published: 2025-07-16

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Tenable researchers found a critical remote-code-execution vulnerability in Oracle Cloud Infrastructure's Code Editor stemming from a missing CSRF check on a file upload router; because Code Editor and Cloud Shell share the same filesystem and session data, an attacker visiting a malicious webpage could upload a malicious file into a victim's Cloud Shell and leverage the victim's OCI permissions to access data or move laterally to Resource Manager, Functions, and Data Science. Oracle patched the issue by requiring a custom CSRF token header, closing the attack vector.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.