Junglewise Threat Intelligence

CVE-2026-83347: Oracle Database Server Net Services denial of service

CVE-2026-83347 · Severity: medium · CVSS 6.5 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Database Server includes a network component (Net Services) used to establish connections to databases. An unauthenticated attacker can exploit a vulnerability in this component over the network to crash the database connection service, rendering it unavailable to legitimate users. The attack requires user interaction and can cause repeated outages.

Technical details

This is a denial-of-service vulnerability in the Oracle Net Services component of Oracle Database Server, affecting versions 23.4.0 through 23.26.3. The vulnerability is easily exploitable and reachable over the network via TCPS (TCP with SSL/TLS) without authentication. However, successful exploitation requires user interaction from someone other than the attacker. A successful attack causes the Oracle Net Services process to hang or crash repeatedly, resulting in complete unavailability of the database connection service. Patch availability has not been confirmed from the advisory text.

Affected products

  • Oracle Database Server 23.4.0-23.26.3

Timeline

  • 2026-09-15: disclosed

References