Executive brief
A vulnerability exists in the Net Service component of Oracle Database Server, which manages network connectivity to the database. An unauthenticated attacker can remotely exploit this flaw to cause the database's networking service to hang or crash repeatedly. This results in a complete denial of service, preventing legitimate users and applications from accessing the database.
Technical details
A vulnerability in the Net Service component of Oracle Database Server (versions 23.4.0 through 23.26.2) allows for a remote denial-of-service attack. The flaw is easily exploitable by an unauthenticated attacker with network access via TLS. Successful exploitation allows the attacker to cause a hang or a frequently repeatable crash of the Net Service, impacting the availability of the database server. The vulnerability is tracked as CVE-2026-46835 and carries a CVSS 3.1 base score of 7.5, specifically targeting the Availability metric.
Affected products
- Oracle Database Server 23.4.0 - 23.26.2
Timeline
- 2026-05-28: disclosed: Initial disclosure by Oracle and NVD publication.