PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-46833 Oracle Corporation CVE debrief

A critical vulnerability in Oracle Database Server's Net Service component, affecting versions 23.4.0 through 23.26.2. The flaw allows unauthenticated network attackers to compromise Net Service via TLS, with potential scope change to impact additional products. Successful exploitation results in complete takeover of the affected service with confidentiality, integrity, and availability impacts. The attack complexity is rated as high, requiring network access but no authentication or user interaction.

Vendor
Oracle Corporation
Product
Oracle Database Server
CVSS
CRITICAL 9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-28
Original CVE updated
2026-05-29
Advisory published
2026-05-28
Advisory updated
2026-05-29

Who should care

Organizations running Oracle Database Server versions 23.4.0 through 23.26.2, particularly those with Net Service exposed to network access. Database administrators, security teams, and compliance officers responsible for Oracle infrastructure security should prioritize this vulnerability due to its critical severity and potential for complete service takeover.

Technical summary

The vulnerability exists in Oracle Database Server's Net Service component across versions 23.4.0-23.26.2. An unauthenticated attacker with network access can exploit this flaw through TLS connections to achieve complete compromise of Net Service. The CVSS 3.1 score of 9.0 reflects high impacts across confidentiality, integrity, and availability with a changed scope indicating potential impact beyond the vulnerable component itself. High attack complexity (AC:H) suggests exploitation requires specialized conditions or techniques.

Defensive priority

critical

Recommended defensive actions

  • Apply Oracle Critical Patch Update for May 2026 immediately to affected Database Server instances
  • Restrict network access to Oracle Net Service listeners to authorized hosts only
  • Enable TLS mutual authentication where feasible to reduce attack surface
  • Monitor for anomalous TLS connections to Database Server Net Service endpoints
  • Review Oracle security alert for patch availability and deployment guidance
  • Assess scope change risk to dependent applications and services

Evidence notes

Oracle security alert referenced as primary source. CVSS 3.1 vector confirms network attack vector with changed scope. Vendor identification marked as low confidence requiring review despite Oracle reference in source material.

Official resources

2026-05-28