Junglewise Threat Intelligence

CVE-2026-47046: Oracle Database Server unauthenticated DoS and data manipulation in RDBMS

CVE-2026-47046 · Severity: high · CVSS 8.2 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability exists in the core engine of Oracle Database Server, which is used by organizations to store and manage critical business data. An attacker can exploit this flaw over the network without needing any login credentials to crash the database service or modify sensitive records. This could lead to significant operational downtime and unauthorized changes to business-critical information.

Technical details

This vulnerability affects the Relational Database Management System (RDBMS) component of Oracle Database Server. It is categorized as easily exploitable, allowing an unauthenticated attacker with network access via the Oracle Net protocol to compromise the system. Successful exploitation can lead to a complete denial-of-service (DoS) through a frequently repeatable crash or system hang. Additionally, the flaw allows for unauthorized integrity impacts, specifically the ability to update, insert, or delete a subset of data within the RDBMS. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Database Server 23.4.0 - 23.26.2

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released

References