Impact
CVE-2026-83333 exposes a flaw in Oracle Net Services that allows an unauthenticated attacker with network access to cause the service to hang or crash repeatedly, resulting in a denial of service. The weakness is a resource exhaustion issue (CWE‑400). The vulnerability does not affect confidentiality or integrity, but it permanently reduces availability for the Oracle Database Server. Successful exploitation leads to interruption of database connectivity for all sessions connected via Oracle Net.
Affected Systems
Affected products are Oracle Corporation’s Oracle Database Server. Versions between 23.4.0 and 23.26.3, inclusive, contain the vulnerable Oracle Net Services component. Any instance running these versions with the Net Services enabled is susceptible.
Risk and Exploitability
The CVSS 3.1 Base Score of 7.5 classifies this as high severity, and the EPSS score of less than 1% indicates a low exploitation probability at this time. The vulnerability is not listed in CISA’s KEV catalogue, yet it can be leveraged over the network without authentication. An attacker simply needs access to the Oracle Net port to trigger the crash. Because there is no authentication requirement or additional host configuration, the risk is significant for exposed or publicly reachable database servers.
OpenCVE Enrichment