Description
Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Net Services. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Net Services. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

CVE-2026-83333 exposes a flaw in Oracle Net Services that allows an unauthenticated attacker with network access to cause the service to hang or crash repeatedly, resulting in a denial of service. The weakness is a resource exhaustion issue (CWE‑400). The vulnerability does not affect confidentiality or integrity, but it permanently reduces availability for the Oracle Database Server. Successful exploitation leads to interruption of database connectivity for all sessions connected via Oracle Net.

Affected Systems

Affected products are Oracle Corporation’s Oracle Database Server. Versions between 23.4.0 and 23.26.3, inclusive, contain the vulnerable Oracle Net Services component. Any instance running these versions with the Net Services enabled is susceptible.

Risk and Exploitability

The CVSS 3.1 Base Score of 7.5 classifies this as high severity, and the EPSS score of less than 1% indicates a low exploitation probability at this time. The vulnerability is not listed in CISA’s KEV catalogue, yet it can be leveraged over the network without authentication. An attacker simply needs access to the Oracle Net port to trigger the crash. Because there is no authentication requirement or additional host configuration, the risk is significant for exposed or publicly reachable database servers.

Generated by OpenCVE AI on September 18, 2026 at 18:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Oracle Database Server to a newer version that includes the Oracle Net Services patch
  • Apply the Oracle Net Services patch detailed in Oracle’s security advisory
  • Restrict Oracle Net Services network access to trusted hosts using firewall rules or ACLs

Generated by OpenCVE AI on September 18, 2026 at 18:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Denial of Service via Oracle Net Services

Wed, 16 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Denial of Service via Oracle Net Services

Wed, 16 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Net Services. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Net Services. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle database - E Net Services
CPEs cpe:2.3:a:oracle:database_-_e_net_services:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle database - E Net Services
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Database - E Net Services
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T23:14:53.131Z

Reserved: 2026-08-31T15:40:57.353Z

Link: CVE-2026-83333

cve-icon Vulnrichment

Updated: 2026-09-15T23:12:54.219Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:46.543

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83333

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T18:15:06Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption