Executive brief
A critical vulnerability has been identified in Oracle Net Services, the component responsible for managing network connections to Oracle Databases. An attacker can exploit this flaw over the network without needing a username or password to steal sensitive data or crash the database service entirely. This could lead to significant data breaches and prolonged business outages for organizations relying on affected Oracle Database versions.
Technical details
A vulnerability exists in the Oracle Net Services component of Oracle Database Server across multiple versions (19c, 21c, and 23c). The flaw is easily exploitable by an unauthenticated attacker with network access via the Oracle Net protocol. Successful exploitation allows the attacker to gain unauthorized access to critical data or all data accessible through Oracle Net Services. Additionally, the attacker can cause a hang or a frequently repeatable crash, resulting in a complete denial of service (DoS) for the affected database instance. The vulnerability is addressed in the Oracle Critical Patch Update (CPU) for July 2026.
Affected products
- Oracle Corporation Oracle Database Server (Oracle Net Services) 19.3-19.31, 21.3-21.22, 23.4.0-23.26.2
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory