PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-47046 Oracle CVE debrief

CVE-2026-47046 is a high-severity vulnerability in the RDBMS component of Oracle Database Server versions 23.4.0-23.26.2. This vulnerability allows unauthenticated attackers with network access via Oracle Net to compromise RDBMS, potentially causing system crashes (complete DOS) and unauthorized data modifications (insert, update, delete). The CVSS 3.1 Base Score is 8.2, indicating high severity. Limited evidence is available on exploitability and affected scope. Oracle Database Server administrators should review and apply vendor patches or updates as available. The CVE record was published on 2026-07-21T22:17:10.233Z and has not been modified since then. Affected product deployments should be inventoried and verified for potential vulnerability. Compensating controls should be implemented to restrict network access to Oracle Net.

Vendor
Oracle
Product
Database Server
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-08-06
Advisory published
2026-07-21
Advisory updated
2026-08-06

Who should care

Oracle Database Server administrators, security teams, and IT professionals responsible for maintaining database security should be aware of this vulnerability and take necessary precautions to mitigate potential risks. Affected operator, platform, vulnerability-management, and security-team impact should be reviewed and addressed.

Technical summary

CVE-2026-47046 is a high-severity vulnerability in the RDBMS component of Oracle Database Server versions 23.4.0-23.26.2. It allows unauthenticated attackers with network access via Oracle Net to compromise RDBMS, potentially causing system crashes (complete DOS) and unauthorized data modifications (insert, update, delete). The CVSS 3.1 Base Score is 8.2, indicating high severity. Limited evidence is available on exploitability and affected scope. Affected product context indicates that Oracle Database Server administrators, security teams, and IT professionals responsible for maintaining database security should be aware of this vulnerability and take necessary precautions to mitigate potential risks.

Defensive priority

High priority due to high CVSS score of 8.2 and potential for unauthorized data access and system disruption.

Recommended defensive actions

  • Inventory and verify Oracle Database Server versions 23.4.0-23.26.2 for potential vulnerability
  • Implement compensating controls to restrict network access to Oracle Net
  • Monitor for suspicious activity and system crashes
  • Apply vendor patches or updates as available
  • Review and update incident response plans for potential data breaches
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance

Evidence notes

The CVE-2026-47046 vulnerability affects Oracle Database Server versions 23.4.0-23.26.2. It allows unauthenticated attackers with network access via Oracle Net to compromise RDBMS, potentially causing system crashes and unauthorized data modifications. The CVSS 3.1 Base Score is 8.2, indicating high severity. Limited evidence is available on exploitability and affected scope.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:10.233Z and has not been modified since then.