Description
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise RDBMS. Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the RDBMS component of Oracle Database Server, permitting a low‑privileged, authenticated user with network connectivity via Oracle Net to compromise the database engine. The flaw is identified as CWE‑269: Privileged Access Management. Successful exploitation can lead to full takeover of the RDBMS, resulting in loss of confidentiality, integrity, and availability for all data stored within the affected instances. The CVSS 3.1 base score of 8.8 reflects high impact across all dimensions and indicates that the flaw is exploitable over the network with relatively low effort.

Affected Systems

Oracle Database Server versions 19.3 through 19.31, 21.3 through 21.22, and 23.4.0 through 23.26.2 are known to be impacted.

Risk and Exploitability

The CVSS score indicates a severe threat, but the EPSS score of less than 1% suggests the likelihood of exploitation is currently very low. The vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation. Attackers would need legitimate, low‑privilege credentials and network access to the Oracle Net listener; no additional prerequisites are disclosed.

Generated by OpenCVE AI on August 2, 2026 at 23:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s most recent patch for the affected Database Server versions as released in the July 2026 CPU.
  • Restrict Oracle Net listener access to trusted network segments and enforce strict firewall rules to limit exposure.
  • Enforce audit logging for all authentication and privilege escalation events, and review logs regularly for anomalous activity.

Generated by OpenCVE AI on August 2, 2026 at 23:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege Authenticated RDBMS Takeover Vulnerability in Oracle Database Server

Sat, 01 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege Authenticated Attacker Can Compromise Oracle RDBMS via Oracle Net

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Oracle database Server
Vendors & Products Oracle database Server

Sun, 26 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege Authenticated Attacker Can Compromise Oracle RDBMS via Oracle Net

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise RDBMS. Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle database - Rdbms
CPEs cpe:2.3:a:oracle:database_-_rdbms:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle database - Rdbms
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Database - Rdbms Database Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T16:14:46.949Z

Reserved: 2026-07-08T15:51:40.517Z

Link: CVE-2026-60175

cve-icon Vulnrichment

Updated: 2026-07-23T16:14:43.347Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T23:45:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management