Junglewise Threat Intelligence

CVE-2026-47038: Oracle Database Server unauthorized data manipulation in RDBMS

CVE-2026-47038 · Severity: low · CVSS 2.7 · Published 2026-07-21

Vendors: Oracle Corporation.

Executive brief

A vulnerability exists in the core database engine of Oracle Database Server, which is used by organizations to store and manage critical business data. A highly privileged user could exploit this flaw to modify, add, or delete specific data within the database without proper authorization. While the risk is limited to users who already have significant access, it could lead to unauthorized data manipulation and loss of data integrity.

Technical details

This vulnerability affects the Relational Database Management System (RDBMS) component of Oracle Database Server. It is classified as an integrity-impacting flaw that allows a high-privileged attacker to perform unauthorized updates, inserts, or deletions of RDBMS-accessible data. The attack vector is network-based via the Oracle Net protocol and requires low complexity to execute. However, the exploit requires the attacker to already possess high-level privileges within the system. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Corporation Database Server 19.3-19.31, 21.3-21.22, 23.4.0-23.26.2

Timeline

  • 2026-07-21: advisory: Initial advisory published by Oracle and NVD

References