Junglewise Threat Intelligence

CVE-2026-47045: Oracle Database Server takeover in JDBC component

CVE-2026-47045 · Severity: medium · CVSS 6.8 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability exists in the JDBC component of Oracle Database Server, which is used to connect applications to the database. A high-privileged attacker could exploit this flaw to take control of the JDBC component, potentially compromising the confidentiality and integrity of the data it handles. Successful exploitation requires a legitimate user to interact with the system, making it a significant risk for organizations relying on these database versions for their operations.

Technical details

A vulnerability in the JDBC component of Oracle Database Server (versions 19.3-19.31, 21.3-21.22, and 23.4.0-23.26.2) allows for a component takeover. The flaw is exploitable by a high-privileged attacker with network access via Oracle Net. While the attack is considered easily exploitable (AC:L), it requires human interaction (UI:R) from a person other than the attacker to succeed. Successful exploitation results in high impacts to confidentiality, integrity, and availability (C:H/I:H/A:H). Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation details.

Affected products

  • Oracle Database Server 19.3-19.31, 21.3-21.22, 23.4.0-23.26.2

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-47045 by Oracle.

References