Junglewise Threat Intelligence

CVE-2026-83350: Oracle Database Server denial of service in Oracle Net Services

CVE-2026-83350 · Severity: high · CVSS 7.5 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Database Server includes a network communication component (Oracle Net Services) that is vulnerable to a denial-of-service attack. An attacker on the network can crash or hang the Oracle Net Services component without authentication, causing the database server to become unavailable and disrupting business operations that depend on database connectivity.

Technical details

This is a denial-of-service vulnerability in the Oracle Net Services component of Oracle Database Server. The vulnerability is easily exploitable and requires only network access via Oracle Net; no authentication or user interaction is required. The root cause involves improper handling of network requests in Oracle Net Services that can be triggered by an unauthenticated attacker to cause a hang or crash of the service. Successful exploitation results in a complete denial of service (DoS) of Oracle Net Services, preventing legitimate clients from connecting to the database. A patch is expected from Oracle as part of their regular security updates.

Affected products

  • Oracle Database Server 21.3-21.23, 23.4.0-23.26.3

Timeline

  • 2026-09-15: disclosed

References