Description
Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Portable Clusterware executes to compromise Portable Clusterware. While the vulnerability is in Portable Clusterware, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Portable Clusterware. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Portable Clusterware, a component of Oracle Database Server, contains an easily exploitable flaw that allows an unauthenticated attacker with access to the physical communication segment attached to the hardware to compromise the clusterware. Exploitation can lead to full takeover of Portable Clusterware, affecting confidentiality, integrity, and availability. The flaw can alter the scope of the affected system, potentially compromising additional Oracle products during an attack.

Affected Systems

Oracle Database Server versions 19.3 through 19.32, 21.3 through 21.23, and 23.4.0 through 23.26.3 are affected. No other vendors or products are listed as impacted.

Risk and Exploitability

The CVSS 3.1 base score of 9.6 indicates a severe vulnerability. By aligning with the CVSS vector AV:A, it is inferred that the attack requires physical proximity to the hardware. The EPSS score of less than 1 percent points to a very low probability of exploitation in the current landscape. The vulnerability is not listed in CISA's KEV catalog. Based on the scope change noted in the description, it is inferred that additional Oracle products that depend on Portable Clusterware could also be affected if the vulnerability is successfully exploited. These factors together underscore the need for urgent attention from impacted organizations.

Generated by OpenCVE AI on August 22, 2026 at 07:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disable or isolate Portable Clusterware if it is not essential to the deployment.
  • Restrict physical access to the hardware communication interfaces that connect to Portable Clusterware and enforce strict personnel controls.
  • Monitor Oracle security advisories and apply any vendor-released patches or updates promptly.

Generated by OpenCVE AI on August 22, 2026 at 07:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Physical Access Exploitation of Oracle Portable Clusterware Leading to Full Clusterware Compromise
Weaknesses CWE-287

Sat, 22 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Physical Access Exploitation of Oracle Portable Clusterware Leading to Full Clusterware Compromise
Weaknesses CWE-287

Thu, 20 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:oracle:database_server:*:*:*:*:*:*:*:*

Thu, 20 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Title Physical Access Exploitation Compromises Clusterware in Oracle Database
Weaknesses CWE-200

Thu, 20 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Oracle database Server
Vendors & Products Oracle database Server

Wed, 19 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Physical Access Exploitation Compromises Clusterware in Oracle Database
Weaknesses CWE-200

Wed, 19 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Clusterware Takeover via Physical Network Access
Weaknesses CWE-284
CWE-285

Wed, 19 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Clusterware Takeover via Physical Network Access
Weaknesses CWE-284
CWE-285

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Portable Clusterware executes to compromise Portable Clusterware. While the vulnerability is in Portable Clusterware, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Portable Clusterware. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle database - Portable Clusterware
CPEs cpe:2.3:a:oracle:database_-_portable_clusterware:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle database - Portable Clusterware
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Database - Portable Clusterware Database Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-22T03:52:28.593Z

Reserved: 2026-08-04T22:06:34.615Z

Link: CVE-2026-71064

cve-icon Vulnrichment

Updated: 2026-08-22T03:52:22.933Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:06.313

Modified: 2026-08-22T04:18:14.427

Link: CVE-2026-71064

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T07:30:17Z

Weaknesses