Executive brief
A vulnerability in the Oracle Database Server's Net Service component allows an attacker to remotely crash the database service. This component is responsible for managing network connectivity between the database and client applications. An exploit could lead to a complete denial of service, preventing legitimate users and applications from accessing critical business data.
Technical details
A vulnerability in the Net Service component of Oracle Database Server (versions 23.4.0-23.26.2) allows for a denial of service. The flaw is easily exploitable by an unauthenticated attacker with network access via TLS. Successful exploitation enables the attacker to cause a hang or a frequently repeatable crash of the Net Service, resulting in a complete loss of availability for the database listener. The vulnerability is tracked as CVE-2026-46834 with a CVSS 3.1 base score of 7.5.
Affected products
- Oracle Database Server 23.4.0-23.26.2
Timeline
- 2026-05-28: disclosed: Initial disclosure by Oracle and NVD publication.