Description
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise RDBMS. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of RDBMS as well as unauthorized update, insert or delete access to some of RDBMS accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).
Published: 2026-07-21
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an unauthenticated attacker with network access to the Oracle Net interface to cause a complete denial of service by repeatedly crashing the RDBMS. The flaw is classified as a resource exhaustion weakness (CWE-400). It also grants the attacker unauthorized ability to update, insert, or delete data that the RDBMS can access. The described impact spans both availability and integrity, as reflected in its CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).

Affected Systems

Oracle Database Server, specifically supported releases from 23.4.0 through 23.26.2. These versions lack the necessary authentication checks for incoming Oracle Net connections, enabling the exploitation path described.

Risk and Exploitability

With a CVSS Base Score of 8.2 and an EPSS score below 1 %, exploitation is considered unlikely but not impossible. The vulnerability is not currently listed in the CISA KEV catalog, but the attack vector is a straightforward network‑based access to Oracle Net without authentication. Successful exploitation grants the attacker both denial of service and the ability to manipulate database records.

Generated by OpenCVE AI on August 4, 2026 at 05:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the June 2026 security patch for Oracle Database Server announced in the Oracle CPU Jul 2026 advisory.
  • Restrict Oracle Net traffic to known, trusted IP addresses or apply firewall rules to limit inbound connections to the database ports.
  • Enable auditing and monitoring on the RDBMS to detect abnormal insert, update, or delete activity and validate data integrity.

Generated by OpenCVE AI on August 4, 2026 at 05:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network-Based Oracle RDBMS Denial of Service and Data Modification Vulnerability

Mon, 03 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network-Based Oracle RDBMS Denial of Service and Data Modification Vulnerability
Weaknesses CWE-284
CWE-306
CWE-399

Mon, 27 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Access Enables Denial of Service and Unauthorized Data Manipulation in Oracle Database Server RDBMS

Fri, 24 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Access Enables Denial of Service and Unauthorized Data Manipulation in Oracle Database Server RDBMS
Weaknesses CWE-284
CWE-306
CWE-399

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise RDBMS. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of RDBMS as well as unauthorized update, insert or delete access to some of RDBMS accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).
First Time appeared Oracle
Oracle database - Rdbms
CPEs cpe:2.3:a:oracle:database_-_rdbms:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle database - Rdbms
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}


Subscriptions

Oracle Database - Rdbms
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:41:23.105Z

Reserved: 2026-05-18T15:55:10.318Z

Link: CVE-2026-47046

cve-icon Vulnrichment

Updated: 2026-07-23T15:41:17.889Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:15:03Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption