Description
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of RDBMS accessible data. CVSS 3.1 Base Score 5.8 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N).
Published: 2026-07-21
Score: 5.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw exists in the RDBMS component of Oracle Database Server, enabling an unauthenticated attacker with network access via Oracle Net to modify database contents. Unauthorized updates, inserts, or deletions of RDBMS data can occur, directly threatening the integrity of stored information. This weakness is a privilege escalation and authorization bypass (CWE‑284). The description indicates that the impact may extend to additional products beyond the database if the attacker succeeds in changing the scope of the vulnerability.

Affected Systems

Oracle Corporation Oracle Database Server versions 19.3 through 19.31, 21.3 through 21.22, and 23.4.0 through 23.26.2 are affected by this vulnerability.

Risk and Exploitability

The CVSS 3.1 Base Score of 5.8 denotes a medium severity focused on integrity. The EPSS score of less than 1% indicates a very low likelihood of widespread automated exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers need only network‑level access to the Oracle Net interface, no authentication, and can exploit the flaw from any remote location that can reach the database server.

Generated by OpenCVE AI on August 4, 2026 at 17:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Database Server patch released in the July 2026 security alert to eliminate the unauthenticated access flaw.
  • Restrict Oracle Net traffic by implementing firewall rules or network controls to limit unauthenticated connections to the database ports.
  • Enforce the principle of least privilege and configure fine‑grained database access controls to reduce the potential impact of any unauthorized data modification attempts.

Generated by OpenCVE AI on August 4, 2026 at 17:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Oracle Database RDBMS Modification via Oracle Net (Scope Change)

Sat, 01 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Oracle Database RDBMS Modification via Oracle Net (Scope Change)

Thu, 30 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Integrity Compromise via Oracle Net RDBMS Component
Weaknesses CWE-285

Fri, 24 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Integrity Compromise via Oracle Net RDBMS Component
Weaknesses CWE-285

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
First Time appeared Oracle database Server
Vendors & Products Oracle database Server

Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of RDBMS accessible data. CVSS 3.1 Base Score 5.8 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N).
First Time appeared Oracle
Oracle database - Rdbms
CPEs cpe:2.3:a:oracle:database_-_rdbms:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle database - Rdbms
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N'}


Subscriptions

Oracle Database - Rdbms Database Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:17:36.027Z

Reserved: 2026-05-18T15:55:10.314Z

Link: CVE-2026-46975

cve-icon Vulnrichment

Updated: 2026-07-23T15:14:44.491Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:02.883

Modified: 2026-08-06T13:54:38.403

Link: CVE-2026-46975

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T18:00:14Z

Weaknesses