Junglewise Threat Intelligence

CVE-2026-46833: Oracle Database Server compromise in Net Service

CVE-2026-46833 · Severity: critical · CVSS 9 · Published 2026-05-28

Vendors: Oracle.

Executive brief

A critical vulnerability exists in the Net Service component of Oracle Database Server, which manages network connectivity between the database and other applications. An unauthenticated attacker could exploit this flaw over the network to gain full control over the service. This could lead to unauthorized access to sensitive data, disruption of database operations, and potential impacts on other integrated business systems.

Technical details

The vulnerability resides in the Net Service component of Oracle Database Server, specifically affecting versions 23.4.0 through 23.26.2. It is classified as a high-complexity attack (AC:H) that can be executed by an unauthenticated attacker with network access via TLS. Successful exploitation results in a complete takeover of the Net Service (C:H/I:H/A:H) and triggers a scope change (S:C), meaning the impact can extend beyond the Net Service to other parts of the infrastructure. While the specific root cause (e.g., buffer overflow or logic error) is not detailed in the advisory, the CVSS vector indicates no user interaction is required. Users are advised to refer to the Oracle May 2026 security alerts for patching information.

Affected products

  • Oracle Database Server 23.4.0-23.26.2

Timeline

  • 2026-05-28: advisory: Initial disclosure by Oracle and NVD publication.

References