PatchSiren cyber security CVE debrief
CVE-2026-47046 Oracle CVE debrief
CVE-2026-47046 is a high-severity vulnerability in the RDBMS component of Oracle Database Server versions 23.4.0-23.26.2. This vulnerability allows unauthenticated attackers with network access via Oracle Net to compromise RDBMS, potentially causing system crashes (complete DOS) and unauthorized data modifications (insert, update, delete). The CVSS 3.1 Base Score is 8.2, indicating high severity. Limited evidence is available on exploitability and affected scope. Oracle Database Server administrators should review and apply vendor patches or updates as available. The CVE record was published on 2026-07-21T22:17:10.233Z and has not been modified since then. Affected product deployments should be inventoried and verified for potential vulnerability. Compensating controls should be implemented to restrict network access to Oracle Net.
- Vendor
- Oracle
- Product
- Database Server
- CVSS
- HIGH 8.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-08-06
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-08-06
Who should care
Oracle Database Server administrators, security teams, and IT professionals responsible for maintaining database security should be aware of this vulnerability and take necessary precautions to mitigate potential risks. Affected operator, platform, vulnerability-management, and security-team impact should be reviewed and addressed.
Technical summary
CVE-2026-47046 is a high-severity vulnerability in the RDBMS component of Oracle Database Server versions 23.4.0-23.26.2. It allows unauthenticated attackers with network access via Oracle Net to compromise RDBMS, potentially causing system crashes (complete DOS) and unauthorized data modifications (insert, update, delete). The CVSS 3.1 Base Score is 8.2, indicating high severity. Limited evidence is available on exploitability and affected scope. Affected product context indicates that Oracle Database Server administrators, security teams, and IT professionals responsible for maintaining database security should be aware of this vulnerability and take necessary precautions to mitigate potential risks.
Defensive priority
High priority due to high CVSS score of 8.2 and potential for unauthorized data access and system disruption.
Recommended defensive actions
- Inventory and verify Oracle Database Server versions 23.4.0-23.26.2 for potential vulnerability
- Implement compensating controls to restrict network access to Oracle Net
- Monitor for suspicious activity and system crashes
- Apply vendor patches or updates as available
- Review and update incident response plans for potential data breaches
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
Evidence notes
The CVE-2026-47046 vulnerability affects Oracle Database Server versions 23.4.0-23.26.2. It allows unauthenticated attackers with network access via Oracle Net to compromise RDBMS, potentially causing system crashes and unauthorized data modifications. The CVSS 3.1 Base Score is 8.2, indicating high severity. Limited evidence is available on exploitability and affected scope.
Official resources
-
CVE-2026-47046 CVE record
CVE.org
-
CVE-2026-47046 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:10.233Z and has not been modified since then.