Description
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows high privileged attacker having None privilege with network access via Oracle Net to compromise RDBMS. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of RDBMS accessible data. CVSS 3.1 Base Score 2.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N).
Published: 2026-07-21
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Database Server’s RDBMS component permits an attacker with high privileges and network access through Oracle Net to perform unauthorized updates, inserts, or deletes on database contents, compromising data integrity.

Affected Systems

Oracle Corporation’s Oracle Database Server is affected in versions 19.3 through 19.31, 21.3 through 21.22, and 23.4.0 through 23.26.2.

Risk and Exploitability

The CVSS v3.1 base score is 2.7, indicating no impact on confidentiality or availability and a low impact on data integrity. The EPSS score is below 1%, showing a very low exploitation probability, and the issue is not listed in the CISA KEV catalog. Attackers would need network connectivity to the database via Oracle Net and elevated privileges to exploit the flaw.

Generated by OpenCVE AI on August 2, 2026 at 23:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Database Server patch releases from Oracle’s update portal to address the RDBMS integrity issue.
  • Configure firewalls or network segmentation to restrict Oracle Net traffic to trusted hosts and networks.
  • Enforce strict role‑based access controls within the database to limit privilege escalation and reduce the attacker’s ability to perform unauthorized modifications.

Generated by OpenCVE AI on August 2, 2026 at 23:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Oracle Database RDBMS Vulnerability Allows Unauthorized Data Modification

Mon, 27 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Oracle Database RDBMS Unauthorized Data Modification via Oracle Net
Weaknesses CWE-284
CWE-862

Fri, 24 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Oracle Database RDBMS Unauthorized Data Modification via Oracle Net
Weaknesses CWE-284
CWE-862

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Oracle database Server
Vendors & Products Oracle database Server

Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows high privileged attacker having None privilege with network access via Oracle Net to compromise RDBMS. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of RDBMS accessible data. CVSS 3.1 Base Score 2.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N).
First Time appeared Oracle
Oracle database - Rdbms
CPEs cpe:2.3:a:oracle:database_-_rdbms:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle database - Rdbms
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Oracle Database - Rdbms Database Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T17:44:40.092Z

Reserved: 2026-05-18T15:55:10.318Z

Link: CVE-2026-47038

cve-icon Vulnrichment

Updated: 2026-07-23T15:31:51.509Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T00:00:04Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function