A critical, network-exploitable vulnerability in Oracle Net Services lets an unauthenticated attacker access sensitive database data and crash the service, carrying a CVSS 3.1 base score of 9.1.
What Is It
CVE-2026-47040 is a vulnerability in the Oracle Net Services component of Oracle Database Server. Per Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via Oracle Net to compromise Oracle Net Services. No privileges, no user interaction, and low attack complexity are required (vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).
Why It Matters
Successful exploitation can result in unauthorized access to critical data, or complete access to all Oracle Net Services accessible data, and the unauthorized ability to cause a hang or a frequently repeatable crash, amounting to a complete denial of service. The high confidentiality and availability impacts drive the 9.1 CRITICAL rating, with a maximum exploitability sub-score of 3.9. Because the attack is remote and requires no authentication, exposed Oracle Net listeners are directly reachable targets.
Note: No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation in the source material.
What's Vulnerable
The affected product is Oracle Net Services (Oracle Corporation). Supported versions that are affected are:
- 19.3 through 19.31
- 21.3 through 21.22
- 23.4.0 through 23.26.2
Patch Status
Oracle addresses this vulnerability in its July 2026 Critical Patch Update. Administrators should consult and apply the fixes documented in the Oracle Critical Patch Update Advisory for July 2026 to remediate affected versions. No separate CISA-mandated required action was provided in the source material.
Sources
- NVD, CVE-2026-47040: https://nvd.nist.gov/vuln/detail/CVE-2026-47040
- Oracle Critical Patch Update Advisory (July 2026): https://www.oracle.com/security-alerts/cpujul2026.html