Description
Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the JDBC executes to compromise JDBC. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JDBC, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all JDBC accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N).
Published: 2026-07-21
Score: 5.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability resides in Oracle Database Server’s JDBC component, allowing an unauthenticated attacker with physical access to the host where JDBC runs to potentially compromise data access. Successful exploitation does not provide arbitrary code execution or denial of service, but it grants read or complete access to JDBC‑exposed data, matching the CWE‑284 Authorization Failure weakness and explaining why improper privilege checks lead to confidentiality violations.

Affected Systems

Oracle Database Server JDBC is affected in versions 19.3 through 19.31, 21.3 through 21.22, and 23.4.0 through 23.26.2. These are supported releases and may be used by multiple applications that rely on JDBC connectivity.

Risk and Exploitability

The CVSS base score of 5.6 with an Adjacent Network (AV:A) vector indicates a medium‑to‑low confidentiality risk. The EPSS score is below 1%, showing a very low probability of current exploitation. The flaw requires physical access and a secondary human actor, so attack complexity is high. It is not listed in CISA KEV, but successful exploitation would allow an attacker to read all JDBC‑accessible data, which may be sensitive.

Generated by OpenCVE AI on August 2, 2026 at 23:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch that addresses the JDBC authorization failure as released in the July 2026 CPU.
  • Limit physical access to Oracle Database Server hosts to authorized personnel only, employing badge or biometric controls.
  • Enforce strict role‑based access control within JDBC configurations to ensure that only users with proper database credentials can access data, directly mitigating CWE‑284.
  • Monitor JDBC access logs and enable audit trails to detect suspicious reads; disable unused JDBC drivers or interfaces to reduce the attack surface.

Generated by OpenCVE AI on August 2, 2026 at 23:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Physical JDBC Exploit

Sun, 26 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Physical JDBC Exploit

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the JDBC executes to compromise JDBC. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JDBC, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all JDBC accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle database - Jdbc
CPEs cpe:2.3:a:oracle:database_-_jdbc:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle database - Jdbc
References
Metrics cvssV3_1

{'score': 5.6, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Database - Jdbc
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T17:06:24.881Z

Reserved: 2026-05-18T15:55:10.319Z

Link: CVE-2026-47061

cve-icon Vulnrichment

Updated: 2026-07-23T16:13:36.717Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T00:00:04Z

Weaknesses