Description
Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCPS to compromise Oracle Net Services. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Net Services. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).
Published: 2026-09-15
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

Vulnerability in Oracle Net Services component of Oracle Database Server allows a network attacker to use TCPS to trigger a hang or crash of the services, resulting in a complete denial of service. Access required no authentication but does require human interaction from a party other than the attacker. The impact is full availability disruption with no known confidentiality or integrity compromise.

Affected Systems

Affected product is Oracle Database Server, specifically the Net Services component, for versions 23.4.0 through 23.26.3.

Risk and Exploitability

The CVSS v3.1 base score is 6.5, reflecting moderate severity primarily due to availability impact. The EPSS score is below 1%, indicating a low probability that the vulnerability will be exploited in the near future. The vulnerability is not listed in CISA’s KEV catalog. An unauthenticated attacker with network connectivity over TCPS can exploit the flaw, but successful attacks also need a second party to provide human interaction. The combination of limited exploitation prerequisites and low EPSS reduces the urgency, but patching remains advisable due to the potential for service disruption.

Generated by OpenCVE AI on September 20, 2026 at 07:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Oracle patch for CVE-2026-83347 released in the Oracle Security Alert.
  • Restrict inbound TCPS traffic to Oracle Net Services by configuring firewall or security group rules to allow only trusted IP ranges.
  • Monitor Oracle Net Services logs for abnormal hang or crash patterns and alert on repeated failures.

Generated by OpenCVE AI on September 20, 2026 at 07:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Title Denial of Service via Unauthenticated TCPS Access in Oracle Net Services

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Oracle Net Services Denial of Service via TCPS
Weaknesses CWE-770 CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Title Oracle Net Services Denial of Service via TCPS
Weaknesses CWE-770

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCPS to compromise Oracle Net Services. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Net Services. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle database - E Net Services
CPEs cpe:2.3:a:oracle:database_-_e_net_services:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle database - E Net Services
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Database - E Net Services
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T16:14:57.443Z

Reserved: 2026-08-31T15:40:57.354Z

Link: CVE-2026-83347

cve-icon Vulnrichment

Updated: 2026-09-18T16:11:52.377Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:48.133

Modified: 2026-09-18T17:17:03.790

Link: CVE-2026-83347

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T08:00:08Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption