CVE-2026-47038
Analyzed Analyzed - Analysis Complete

RDBMS Component Unauthorized Data Manipulation in Oracle Database Server

Vulnerability report for CVE-2026-47038, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-21

Last updated on: 2026-08-06

Assigner: Oracle

Description

Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows high privileged attacker having None privilege with network access via Oracle Net to compromise RDBMS. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of RDBMS accessible data. CVSS 3.1 Base Score 2.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-21
Last Modified
2026-08-06
Generated
2026-08-11
AI Q&A
2026-07-22
EPSS Evaluated
2026-08-09
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
oracle database_server From 19.3 (inc) to 19.31 (inc)
oracle database_server From 21.3 (inc) to 21.22 (inc)
oracle database_server From 23.4 (inc) to 23.26.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a vulnerability in the RDBMS component of Oracle Database Server affecting versions 19.3-19.31, 21.3-21.22, and 23.4.0-23.26.2. It allows a high privileged attacker with network access to perform unauthorized updates, inserts, or deletes on some database-accessible data.

Detection Guidance

This vulnerability requires high privileged access and network access via Oracle Net. Detection involves monitoring Oracle Database Server logs for unauthorized data modifications or unusual network access patterns. Check Oracle alert logs and audit logs for suspicious activities related to data changes.

Impact Analysis

The impact includes unauthorized modification of data, which could lead to data corruption or integrity issues. However, the attack requires high privileges and network access, reducing the risk for most users.

Compliance Impact

This vulnerability could potentially violate compliance requirements that mandate data integrity and protection, such as GDPR or HIPAA, if exploited to alter sensitive data. However, the low CVSS score suggests limited impact.

Mitigation Strategies

Apply the latest Oracle Critical Patch Update (CPU) for your affected Oracle Database Server version to address the RDBMS vulnerability. Ensure only trusted users have high privileges and restrict network access via Oracle Net to minimize attack surface.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-47038. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart