Executive brief
A vulnerability exists in the core database engine of Oracle Database Server, which is used by organizations to store and manage critical business data. An unauthorized person could remotely connect to the database and modify, add, or delete certain records without needing a username or password. This could lead to data corruption or unauthorized changes to business records, potentially impacting other integrated systems.
Technical details
This vulnerability resides in the Relational Database Management System (RDBMS) component of Oracle Database Server. It is classified as an integrity-impacting flaw that allows an unauthenticated attacker with network access via the Oracle Net protocol to compromise the system. The exploit does not require user interaction or special privileges (PR:N/UI:N). Successful exploitation enables unauthorized update, insert, or delete access to a subset of RDBMS-accessible data. Notably, the vulnerability carries a 'Scope Change' (S:C), meaning a successful attack can impact components or products beyond the immediate database environment. Patches are typically delivered via Oracle's Critical Patch Update (CPU) program.
Affected products
- Oracle Database Server 19.3-19.31, 21.3-21.22, 23.4.0-23.26.2
Timeline
- 2026-07-21: disclosed: Initial publication of CVE-2026-46975 by Oracle
- 2026-07-21: advisory: NVD record published