Description
Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Net Services. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Net Services. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service on Oracle Net Services
Action: Immediate Patch
AI Analysis

Impact

A flaw exists in the Oracle Net Services component of Oracle Database Server that permits an unauthenticated attacker to send specially crafted requests over the network. The malicious request triggers uncontrolled resource consumption (CWE‑400), causing the Net Services process to hang or crash, resulting in a full denial of service that renders the database unavailable. Since no credentials or privileged access are required, the vulnerability has a high impact on availability while not directly affecting confidentiality or integrity.

Affected Systems

The vulnerability affects Oracle Database Server, specifically the Net Services component. Supported versions that are vulnerable include 21.3 through 21.23 and 23.4.0 through 23.26.3.

Risk and Exploitability

The CVSS base score of 7.5 indicates a high severity, and the EPSS score of less than 1% suggests that exploitation attempts are currently rare. Although the vulnerability is not listed in the CISA KEV catalog, an unauthenticated attacker with network connectivity to Oracle Net Services can trigger the flaw and cause a continuous denial of service. The flaw is exploitable through unrestricted network access, making it a significant risk for organizations that expose the service without proper access controls.

Generated by OpenCVE AI on September 18, 2026 at 16:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑released patch that resolves the uncontrolled resource consumption flaw in Oracle Net Services (CWE‑400).
  • If a patch is not immediately available, restrict network access to Oracle Net Services by configuring firewall or ACL rules to limit connections to trusted IP ranges.
  • Continuously monitor database and network logs for repeated connection failures, hangs, or service crashes to detect potential exploitation attempts.

Generated by OpenCVE AI on September 18, 2026 at 16:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Title Unrestricted Network Access to Oracle Net Services Allows Unauthenticated Denial of Service

Wed, 16 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Title Unrestricted Network Access to Oracle Net Services Allows Unauthenticated Denial of Service

Wed, 16 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Oracle Corporation
Oracle Corporation oracle Database Server
Vendors & Products Oracle Corporation
Oracle Corporation oracle Database Server

Wed, 16 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Net Services. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Net Services. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle database - E Net Services
CPEs cpe:2.3:a:oracle:database_-_e_net_services:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle database - E Net Services
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Database - E Net Services
Oracle Corporation Oracle Database Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T23:14:52.829Z

Reserved: 2026-08-31T15:40:57.354Z

Link: CVE-2026-83350

cve-icon Vulnrichment

Updated: 2026-09-15T23:12:47.692Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:48.470

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83350

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T16:15:10Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption