CVE-2026-46833
Net Service Component Takeover in Oracle Database Server
Publication date: 2026-05-28
Last updated on: 2026-05-28
Assigner: Oracle
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| oracle | database_server | From 23.4.0 (inc) to 23.26.2 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
This vulnerability allows an unauthenticated attacker with network access via TLS to compromise the Net Service component of Oracle Database Server, potentially leading to a complete takeover of the Net Service.
Given the high impact on confidentiality, integrity, and availability (CVSS score 9.0), successful exploitation could lead to unauthorized access or manipulation of sensitive data.
Such a compromise could negatively affect compliance with data protection regulations and standards like GDPR and HIPAA, which require safeguarding sensitive personal and health information against unauthorized access and ensuring data integrity and availability.
Can you explain this vulnerability to me?
This vulnerability exists in the Net Service component of the Oracle Database Server, affecting versions 23.4.0 through 23.26.2. It is difficult to exploit but allows an unauthenticated attacker with network access via TLS to compromise the Net Service.
Although the vulnerability is specifically in Net Service, successful exploitation can impact additional products due to a scope change, potentially leading to a takeover of the Net Service.
How can this vulnerability impact me? :
Successful exploitation of this vulnerability can result in a complete takeover of the Net Service component, which can severely impact confidentiality, integrity, and availability of the affected system.
- Confidentiality impact: High
- Integrity impact: High
- Availability impact: High