Impact
A weakness in Oracle Net Services allows an attacker who can reach the Oracle Net interface to bypass authentication and gain unrestricted access to all data that the service can see, or to cause the service to hang or crash repeatedly, resulting in a denial of service. This is an authentication bypass (CWE-306) that can expose critical database information or disrupt service availability. The CVE lists a CVSS base score of 9.1, indicating high confidentiality and availability impacts.
Affected Systems
Oracle Corporation’s Oracle Net Services component of Oracle Database Server is affected. Versions 19.3 through 19.31, 21.3 through 21.22, and 23.4.0 through 23.26.2 are vulnerable. Users running any of these releases should review Oracle’s CPU Jul 2026 advisory to confirm whether their installations are impacted.
Risk and Exploitability
The vulnerability can be triggered remotely by sending the appropriate traffic over Oracle Net. Because authentication is not required, any host with network connectivity to the service can exploit it. The CVSS score of 9.1 reflects a top‑tier severity, but the EPSS score of less than 1% indicates that exploitation is considered rare at this time, and the flaw is not listed in CISA’s KEV catalog. Nonetheless, the ease of exploitation and the potential to compromise sensitive data or cause service downtime make it a significant threat that should be addressed promptly.
OpenCVE Enrichment