PatchSiren cyber security CVE debrief
CVE-2026-46833 Oracle Corporation CVE debrief
A critical vulnerability in Oracle Database Server's Net Service component, affecting versions 23.4.0 through 23.26.2. The flaw allows unauthenticated network attackers to compromise Net Service via TLS, with potential scope change to impact additional products. Successful exploitation results in complete takeover of the affected service with confidentiality, integrity, and availability impacts. The attack complexity is rated as high, requiring network access but no authentication or user interaction.
- Vendor
- Oracle Corporation
- Product
- Oracle Database Server
- CVSS
- CRITICAL 9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-28
- Original CVE updated
- 2026-05-29
- Advisory published
- 2026-05-28
- Advisory updated
- 2026-05-29
Who should care
Organizations running Oracle Database Server versions 23.4.0 through 23.26.2, particularly those with Net Service exposed to network access. Database administrators, security teams, and compliance officers responsible for Oracle infrastructure security should prioritize this vulnerability due to its critical severity and potential for complete service takeover.
Technical summary
The vulnerability exists in Oracle Database Server's Net Service component across versions 23.4.0-23.26.2. An unauthenticated attacker with network access can exploit this flaw through TLS connections to achieve complete compromise of Net Service. The CVSS 3.1 score of 9.0 reflects high impacts across confidentiality, integrity, and availability with a changed scope indicating potential impact beyond the vulnerable component itself. High attack complexity (AC:H) suggests exploitation requires specialized conditions or techniques.
Defensive priority
critical
Recommended defensive actions
- Apply Oracle Critical Patch Update for May 2026 immediately to affected Database Server instances
- Restrict network access to Oracle Net Service listeners to authorized hosts only
- Enable TLS mutual authentication where feasible to reduce attack surface
- Monitor for anomalous TLS connections to Database Server Net Service endpoints
- Review Oracle security alert for patch availability and deployment guidance
- Assess scope change risk to dependent applications and services
Evidence notes
Oracle security alert referenced as primary source. CVSS 3.1 vector confirms network attack vector with changed scope. Vendor identification marked as low confidence requiring review despite Oracle reference in source material.
Official resources
-
CVE-2026-46833 CVE record
CVE.org
-
CVE-2026-46833 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
2026-05-28