Description
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31 and 23.4.0-23.26.2. Easily exploitable vulnerability allows low privileged attacker having Execute DBMS_CLOUD privilege with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the RDBMS component of Oracle Database Server allows a low‑privileged attacker who has the Execute privilege on DBMS_CLOUD to compromise the database server. The flaw permits the attacker to perform arbitrary actions that can result in a full takeover of the RDBMS, causing complete confidentiality, integrity, and availability loss. The CVSS 3.1 Base Score of 9.9 underscores the severity and indicates that the vulnerability can change the scoped impact to affect other Oracle products.

Affected Systems

Oracle Database Server versions 19.3 through 19.31 and 23.4.0 through 23.26.2 are affected. Users of these releases must determine whether they are deployed with the vulnerable component.

Risk and Exploitability

The exploit is readily usable over the network via Oracle Net and requires only the Execute privilege on DBMS_CLOUD. Once accessed, the blast radius extends to the entire database. The EPSS score is less than 1%, indicating a low probability of widespread exploitation, but the high CVSS score and the ability to cause a full takeover make it a top priority for remediation. The vulnerability is not listed in CISA KEV, and the ability to impact additional products may increase its overall risk.

Generated by OpenCVE AI on August 5, 2026 at 01:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch provided in Oracle's CPU July 2026 update to address CVE‑2026‑61211.
  • Revoke the Execute privilege on DBMS_CLOUD from all low‑privileged accounts or restrict its use to trusted services.
  • Limit inbound Oracle Net traffic to the database server to trusted hosts and networks, using firewalls or VPNs.
  • Monitor database logs for abnormal DBMS_CLOUD activity and enforce logging of privilege usage.

Generated by OpenCVE AI on August 5, 2026 at 01:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title DBMS_CLOUD Execute Privilege Enables Full RDBMS Takeover

Mon, 27 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege DBMS_CLOUD Escalation Enables RDBMS Takeover

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege DBMS_CLOUD Escalation Enables RDBMS Takeover

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31 and 23.4.0-23.26.2. Easily exploitable vulnerability allows low privileged attacker having Execute DBMS_CLOUD privilege with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle database - Rdbms
CPEs cpe:2.3:a:oracle:database_-_rdbms:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle database - Rdbms
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Database - Rdbms
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T18:29:56.432Z

Reserved: 2026-07-08T15:52:20.741Z

Link: CVE-2026-61211

cve-icon Vulnrichment

Updated: 2026-07-22T18:29:43.251Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T01:15:03Z

Weaknesses