Description
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Difficult to exploit vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in the RDBMS component of Oracle Database Server that allows a low‑privileged authenticated user with network access via Oracle Net to compromise the database management system. Successful exploitation can result in full takeover of the RDBMS, potentially affecting confidentiality, integrity, and availability, and may extend to other products that depend on the RDBMS, indicating a scope change.

Affected Systems

Oracle Corporation’s Oracle Database Server, specifically the supported versions identified as 23.4.0 through 23.26.3.

Risk and Exploitability

The vulnerability carries a CVSS 3.1 base score of 8.5, reflecting high confidentiality, integrity, and availability impact. EPSS score is less than 1%, and the vulnerability is not listed in CISA’s KEV catalog, but the attack vector is remote over the network for authenticated users. Because the attacker only needs low‑privilege authentication, the risk of exploitation is significant, and the potential for system‑wide compromise warrants immediate attention.

Generated by OpenCVE AI on August 20, 2026 at 19:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch for CVE-2026-71062 to Oracle Database Server
  • Restrict Oracle Net port access to trusted networks and enforce strict firewall rules
  • Monitor database activity for anonymous or unusual privilege escalation attempts, and enable comprehensive auditing

Generated by OpenCVE AI on August 20, 2026 at 19:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation Enables Full Takeover of Oracle Database Server RDBMS

Thu, 20 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:oracle:database_server:*:*:*:*:*:*:*:*

Thu, 20 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation Allowing RDBMS Takeover via Oracle Net

Thu, 20 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Oracle database Server
Vendors & Products Oracle database Server

Wed, 19 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation Allowing RDBMS Takeover via Oracle Net

Wed, 19 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 19 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Title Authenticated User RDBMS Compromise via Oracle Net
Weaknesses CWE-284
CWE-306

Wed, 19 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Authenticated User RDBMS Compromise via Oracle Net
Weaknesses CWE-284
CWE-306

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Difficult to exploit vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle database - Rdbms
CPEs cpe:2.3:a:oracle:database_-_rdbms:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle database - Rdbms
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Database - Rdbms Database Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T03:56:47.697Z

Reserved: 2026-08-04T22:06:34.614Z

Link: CVE-2026-71062

cve-icon Vulnrichment

Updated: 2026-08-19T15:47:41.833Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:06.080

Modified: 2026-08-20T15:09:41.410

Link: CVE-2026-71062

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T19:30:05Z

Weaknesses