Executive brief
A critical vulnerability exists in the Oracle Database Server, a widely used system for managing corporate data and applications. An attacker with low-level access can exploit this flaw to take complete control of the database system. This could lead to the theft of sensitive information, unauthorized modification of records, or a total shutdown of database services, potentially impacting other connected business systems.
Technical details
A vulnerability in the RDBMS component of Oracle Database Server (versions 19.3-19.31 and 23.4.0-23.26.2) allows for a complete system compromise. The issue is rooted in the DBMS_CLOUD package, where an attacker with 'Execute DBMS_CLOUD' privileges can leverage network access via Oracle Net to exploit the system. The vulnerability is characterized by a scope change (S:C), meaning a successful exploit can impact components beyond the RDBMS itself. It requires low privileges and no user interaction, leading to a full loss of confidentiality, integrity, and availability. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation.
Affected products
- Oracle Database Server 19.3-19.31, 23.4.0-23.26.2
Timeline
- 2026-07-21: advisory: Initial disclosure by Oracle and NVD publication.