Junglewise Threat Intelligence

CVE-2026-83333: Oracle Database Server Net Services denial of service

CVE-2026-83333 · Severity: high · CVSS 7.5 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Database Server includes a network communication component (Oracle Net Services) that handles remote connections to databases. An unauthenticated attacker with network access can trigger a complete crash or hang of this service, disrupting database availability. No authentication is required and the attack is straightforward to execute.

Technical details

The vulnerability is a denial-of-service flaw in the Oracle Net Services component of Oracle Database Server. An unauthenticated attacker with network access via Oracle Net can send specially crafted requests to trigger an unhandled condition, causing the service to hang or crash completely, resulting in unavailability of the database. The attack requires no authentication or user interaction and is easily exploitable. Affected versions include 23.4.0 through 23.26.3. Patches are expected to be available from Oracle.

Affected products

  • Oracle Database Server 23.4.0 through 23.26.3

Timeline

  • 2026-09-15: disclosed

References