Junglewise Threat Intelligence

CVE-2026-60175: Oracle Database Server RDBMS compromise via Oracle Net

CVE-2026-60175 · Severity: high · CVSS 8.8 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability exists in the core engine of the Oracle Database Server, which is used by organizations to store and manage critical business data. An individual with basic user access to the database could exploit this flaw over the network to take full control of the database system. This could lead to the unauthorized viewing of sensitive information, data deletion, or a complete shutdown of database services.

Technical details

This vulnerability affects the Relational Database Management System (RDBMS) component of Oracle Database Server. It is classified as easily exploitable, requiring only low-privileged 'Authenticated User' credentials and network connectivity via the Oracle Net protocol. A successful exploit allows an attacker to bypass security controls to achieve a full compromise of the RDBMS, impacting confidentiality, integrity, and availability. The issue affects versions 19c (19.3-19.31), 21c (21.3-21.22), and 23c (23.4.0-23.26.2). Users are advised to apply the relevant patches from the Oracle Critical Patch Update (CPU).

Affected products

  • Oracle Database Server 19.3-19.31, 21.3-21.22, 23.4.0-23.26.2

Timeline

  • 2026-07-21: disclosed: Initial advisory publication by Oracle
  • 2026-07-21: advisory: NVD record created

References