Description
Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Net Services. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Net Services accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Net Services. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).
Published: 2026-07-21
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A weakness in Oracle Net Services allows an attacker who can reach the Oracle Net interface to bypass authentication and gain unrestricted access to all data that the service can see, or to cause the service to hang or crash repeatedly, resulting in a denial of service. This is an authentication bypass (CWE-306) that can expose critical database information or disrupt service availability. The CVE lists a CVSS base score of 9.1, indicating high confidentiality and availability impacts.

Affected Systems

Oracle Corporation’s Oracle Net Services component of Oracle Database Server is affected. Versions 19.3 through 19.31, 21.3 through 21.22, and 23.4.0 through 23.26.2 are vulnerable. Users running any of these releases should review Oracle’s CPU Jul 2026 advisory to confirm whether their installations are impacted.

Risk and Exploitability

The vulnerability can be triggered remotely by sending the appropriate traffic over Oracle Net. Because authentication is not required, any host with network connectivity to the service can exploit it. The CVSS score of 9.1 reflects a top‑tier severity, but the EPSS score of less than 1% indicates that exploitation is considered rare at this time, and the flaw is not listed in CISA’s KEV catalog. Nonetheless, the ease of exploitation and the potential to compromise sensitive data or cause service downtime make it a significant threat that should be addressed promptly.

Generated by OpenCVE AI on August 4, 2026 at 05:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch or upgrade to a version released in Oracle’s CPU Jul 2026 advisory, which contains the fix for this authentication bypass.
  • If a patch is not yet available, isolate the Oracle Net service by configuring network firewalls or host‑based controls to block unauthenticated traffic to the Oracle Net port, thereby preventing remote exploitation.
  • Maintain strict access controls on Oracle Net accounts and audit the service for any unauthorized connection attempts.

Generated by OpenCVE AI on August 4, 2026 at 05:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Authentication Bypass in Oracle Net Services

Thu, 30 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Authentication Bypass in Oracle Net Services

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Net Services. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Net Services accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Net Services. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).
First Time appeared Oracle
Oracle net Services
CPEs cpe:2.3:a:oracle:net_services:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle net Services
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Subscriptions

Oracle Database Server Net Services
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:37:04.597Z

Reserved: 2026-05-18T15:55:10.318Z

Link: CVE-2026-47040

cve-icon Vulnrichment

Updated: 2026-07-23T15:36:59.643Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:09.667

Modified: 2026-08-06T13:53:17.670

Link: CVE-2026-47040

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:15:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function