Description
Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Portable Clusterware executes to compromise Portable Clusterware. While the vulnerability is in Portable Clusterware, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Portable Clusterware. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Portable Clusterware component of Oracle Database Server, enabling an unauthenticated attacker who has access to the physical communication segment attached to the hardware where the Portable Clusterware runs to compromise the clusterware. If successfully exploited the attacker can take over Portable Clusterware, resulting in the compromise of confidentiality, integrity, and availability of the affected database environment. The weakness involves improper access control that allows local physical attackers to gain privileged control over the clusterware services.

Affected Systems

Affected are Oracle Corporation’s Oracle Database Server products. Specifically, Portable Clusterware versions 19.3 through 19.32, 21.3 through 21.23, and 23.4.0 through 23.26.3 are vulnerable. The cited advisory indicates that successful exploitation could also impact additional Oracle products beyond Portable Clusterware, expanding the potential scope of impact.

Risk and Exploitability

The CVSS v3.1 base score is 9.6 with an Availability Impact and a Confidentiality, Integrity, and Availability compromise. The attack vector is AV:A—adjacent local—meaning the attacker must have physical or local network access to the communication segment. EPSS score of < 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog, indicating it has not yet been observed in the wild but could be high severity if an exploited code path is triggered. The nature of the flaw implies a likely exploitation path that requires physical proximity or control over the local network segment, but once that condition is met, the attacker can achieve full control of the Portable Clusterware services.

Generated by OpenCVE AI on August 20, 2026 at 18:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install the Oracle patch set that addresses CVE‑2026‑71063 for the affected Portable Clusterware components as described in the Oracle security alert linked in the advisory.
  • If a patch is not yet available, enforce strict network segmentation so that the physical communication segment is isolated from the rest of the environment, applying firewall rules or VLAN restrictions to block access from untrusted hosts.
  • Monitor the communication segment for unauthorized activity and review Oracle logs for unexpected use of Portable Clusterware services; trigger alerts for any suspicious behavior.
  • Consider disabling any unused Portable Clusterware services or components as a temporary mitigating control.

Generated by OpenCVE AI on August 20, 2026 at 18:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Oracle Corporation
Oracle Corporation oracle Database Server
Vendors & Products Oracle Corporation
Oracle Corporation oracle Database Server

Thu, 20 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Adjacent Access Allows Full Control of Oracle Portable Clusterware

Thu, 20 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Oracle database Server
CPEs cpe:2.3:a:oracle:database_server:*:*:*:*:*:*:*:*
Vendors & Products Oracle database Server

Thu, 20 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Physical Access Exploitation of Oracle Portable Clusterware Enables Full Takeover

Wed, 19 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Physical Access Exploitation of Oracle Portable Clusterware Enables Full Takeover

Wed, 19 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 19 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Physical Access Allows Takeover of Oracle Database Portable Clusterware
Weaknesses CWE-269
CWE-285

Wed, 19 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Physical Access Allows Takeover of Oracle Database Portable Clusterware
Weaknesses CWE-269
CWE-285

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Portable Clusterware executes to compromise Portable Clusterware. While the vulnerability is in Portable Clusterware, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Portable Clusterware. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle database - Portable Clusterware
CPEs cpe:2.3:a:oracle:database_-_portable_clusterware:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle database - Portable Clusterware
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Database - Portable Clusterware Database Server
Oracle Corporation Oracle Database Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T16:03:41.812Z

Reserved: 2026-08-04T22:06:34.614Z

Link: CVE-2026-71063

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:06.193

Modified: 2026-08-20T15:09:36.467

Link: CVE-2026-71063

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:32:06Z

Weaknesses