Junglewise Threat Intelligence

CVE-2026-47061: Oracle Database Server information disclosure in JDBC

CVE-2026-47061 · Severity: medium · CVSS 5.6 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability exists in the JDBC component of Oracle Database Server, which is the standard interface used by applications to communicate with the database. An attacker with access to the local network could potentially gain unauthorized access to sensitive business data. Exploitation is considered difficult as it requires specific network positioning and interaction from a legitimate user.

Technical details

This vulnerability in the Oracle JDBC driver is characterized by a high attack complexity and requires user interaction. An unauthenticated attacker must be located on the same physical or logical network segment (Adjacent vector) as the hardware executing the JDBC code. The vulnerability allows for a 'scope change,' meaning a successful exploit can impact components beyond the JDBC driver itself, potentially leading to unauthorized access to all data accessible via the JDBC connection. While specific root cause details (such as the CWE) are not provided in the advisory, the CVSS vector indicates a confidentiality impact without affecting integrity or availability. Users should refer to the Oracle July 2026 Critical Patch Update for remediation steps.

Affected products

  • Oracle Database Server (JDBC) 19.3-19.31, 21.3-21.22, 23.4.0-23.26.2

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References