Junglewise Threat Intelligence

CVE-2026-71102: Oracle Database Server Portable Clusterware HTTP access control bypass

CVE-2026-71102 · Severity: critical · CVSS 9.1 · Published 2026-08-18

Vendors: Oracle.

Executive brief

Oracle Database Server's Portable Clusterware component contains a flaw that allows attackers to access the system over the network without authentication. An attacker can exploit this vulnerability to create, modify, or delete critical data in the database cluster and cause the system to crash or hang, disrupting business operations and potentially compromising data integrity.

Technical details

The vulnerability is an easily exploitable access control bypass in Oracle Database Server's Portable Clusterware component that can be triggered over HTTP by an unauthenticated, network-connected attacker. No user interaction or authentication is required to exploit this flaw. Successful exploitation allows unauthorized modification or deletion of critical data and unauthorized ability to cause denial of service (hang or crash) of the Portable Clusterware. The affected versions include 19.3–19.32, 21.3–21.23, and 23.4.0–23.26.3. Patch availability status is not specified in the provided advisory.

Affected products

  • Oracle Database Server 19.3–19.32, 21.3–21.23, 23.4.0–23.26.3

Timeline

  • 2026-08-18: disclosed

References