Description
Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Portable Clusterware. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Portable Clusterware accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Portable Clusterware. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).
Published: 2026-08-18
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CVE identifies an easily exploitable flaw in the Portable Clusterware component of Oracle Database Server that allows an unauthenticated attacker with network access via HTTP to modify, delete, or create critical data. Successful exploitation can also trigger a hang or crash, resulting in a complete denial of service. The weakness corresponds to improper access control (CWE‑284), enabling attackers to bypass authentication and directly affect system integrity and availability. Because the vulnerability can be triggered remotely without credentials, it provides a straightforward entry point for attackers to compromise clusterware data and stability.

Affected Systems

Oracle Database Server versions 19.3 through 19.32, 21.3 through 21.23, and 23.4.0 through 23.26.3 include the vulnerable Portable Clusterware component. The vulnerability is present in all Oracle Database Server deployments using this component.

Risk and Exploitability

The vulnerability has a CVSS v3.1 base score of 9.1, indicating high impact on integrity and availability. The EPSS score of 0.00407 (<1%) suggests a very low exploitation probability, but the high severity and unauthenticated HTTP access still present a risk. The vulnerability is not listed in the CISA KEV catalog, but the CVSS score and unauthenticated HTTP access mean that attackers can reach the target without prior compromise, increasing the risk. Because the attack requires only a network connection to HTTP and no credentials, it is likely to be exploitable from the Internet or internal networks, especially where the Portable Clusterware service is exposed.

Generated by OpenCVE AI on August 20, 2026 at 22:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch for Portable Clusterware that addresses CVE‑2026‑71102
  • Restrict HTTP access to the Portable Clusterware interface by firewall or network segmentation to trusted hosts only
  • Monitor logs for unauthorized access attempts to clusterware and reject unauthenticated requests
  • Follow Oracle security advisories for future updates

Generated by OpenCVE AI on August 20, 2026 at 22:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Modification and Denial of Service in Oracle Portable Clusterware

Thu, 20 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Oracle database Server
CPEs cpe:2.3:a:oracle:database_server:*:*:*:*:*:*:*:*
Vendors & Products Oracle database Server

Thu, 20 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Modification and Denial of Service in Oracle Portable Clusterware

Thu, 20 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit in Oracle Portable Clusterware Allowing Data Modification and Denial of Service

Wed, 19 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit in Oracle Portable Clusterware Allowing Data Modification and Denial of Service
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Portable Clusterware. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Portable Clusterware accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Portable Clusterware. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).
First Time appeared Oracle
Oracle database - Portable Clusterware
CPEs cpe:2.3:a:oracle:database_-_portable_clusterware:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle database - Portable Clusterware
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Oracle Database - Portable Clusterware Database Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T16:01:17.289Z

Reserved: 2026-08-04T22:06:34.617Z

Link: CVE-2026-71102

cve-icon Vulnrichment

Updated: 2026-08-19T15:07:07.905Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:10.493

Modified: 2026-08-20T15:09:08.437

Link: CVE-2026-71102

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T23:00:07Z

Weaknesses