Description
Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Net Services. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Net Services. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Availability)
Action: Patch
AI Analysis

Impact

The vulnerability resides in the Oracle Net Services component of Oracle Database Server. It allows an unauthenticated attacker with network access over Oracle Net to cause the service to hang or crash repeatedly, resulting in a complete denial of service. The weakness is a lack of resource consumption controls that can be triggered by crafted input, mapping to the CWE‑400 category of Uncontrolled Resource Consumption.

Affected Systems

Affected products include Oracle Database Server’s Oracle Net Services. Versions impacted are 19.3 through 19.32, 21.3 through 21.23, and 23.4.0 through 23.26.3.

Risk and Exploitability

The CVSS base score of 7.5 indicates a high severity with a pivotal availability impact. The EPSS score of less than 1 percent reflects a low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalogue. Exploitation requires only network connectivity to an untrusted Oracle remote host that can contact the database service, making the threat most serious where Oracle Net Services is exposed to untrusted networks. The impact could be system‑wide service outages if the attacker succeeds.

Generated by OpenCVE AI on September 18, 2026 at 15:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any available Oracle Database Server patch or update that addresses this vulnerability.
  • Restart Oracle Net Services after patching to clear any hanging processes or corrupted state.
  • Implement network segmentation or firewall rules to restrict inbound traffic to the Oracle Net port only to trusted hosts, reducing the surface for attack.

Generated by OpenCVE AI on September 18, 2026 at 15:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Oracle database Server
Vendors & Products Oracle database Server

Fri, 18 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Oracle Net Services Denial of Service via Resource Exhaustion

Wed, 16 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Oracle Net Services Denial of Service via Resource Exhaustion

Wed, 16 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Net Services. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Net Services. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle database - E Net Services
CPEs cpe:2.3:a:oracle:database_-_e_net_services:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle database - E Net Services
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Database - E Net Services Database Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T23:14:52.978Z

Reserved: 2026-08-31T15:40:57.354Z

Link: CVE-2026-83349

cve-icon Vulnrichment

Updated: 2026-09-15T23:12:51.098Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:48.360

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83349

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T02:45:11Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption