Junglewise Threat Intelligence

CVE-2026-83349: Oracle Database Server Net Services denial of service

CVE-2026-83349 · Severity: high · CVSS 7.5 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Database Server includes a network communication component called Net Services that handles connections between clients and the database. An unauthenticated attacker on the network can exploit a flaw in this component to crash or freeze the service, preventing legitimate users from accessing the database and causing operational downtime.

Technical details

This is a denial-of-service vulnerability in the Oracle Net Services component of Oracle Database Server. The flaw is easily exploitable and requires only network access to the Oracle Net port; no authentication or user interaction is required. An attacker can send specially crafted network packets via Oracle Net protocol to trigger a hang or crash of the Net Services process, resulting in complete unavailability. The vulnerability affects versions 19.3-19.32, 21.3-21.23, and 23.4.0-23.26.3. Patches from Oracle are expected as part of their regular security updates.

Affected products

  • Oracle Database Server 19.3-19.32, 21.3-21.23, 23.4.0-23.26.3

Timeline

  • 2026-09-15: disclosed

References