PT-2026-44526 · Oracle · Oracle Database Server+1

·

CVE-2026-46833

·

Published

2026-05-28

·

Updated

2026-07-21

CVSS v3.1

9.0

Critical

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Oracle Database Server versions 23.4.0 through 23.26.2
Description A flaw in the Net Service component allows an unauthenticated attacker with network access via TLS to compromise the service. Although difficult to exploit, a successful attack can result in a complete takeover of the Net Service and may significantly impact additional products due to a scope change.
Recommendations Update Oracle Database Server versions 23.4.0 through 23.26.2 to the latest security updates provided by Oracle.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-46833

Affected Products

Oracle Database Server
Database Server