Remote Code Execution Vulnerability in Oracle Database Server
CVE-2026-46975

5.8MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-46975?

The vulnerability in the RDBMS component of Oracle Database Server allows an unauthenticated attacker with network access via Oracle Net to manipulate the database. It affects several versions of the database, providing a potential pathway for unauthorized data modification, including the ability to update, insert, or delete data within accessible areas of the RDBMS. Exploiting this flaw could lead to significant impact beyond the RDBMS itself, threatening the integrity of connected applications and data.

Affected Version(s)

Oracle Database Server 19.3 <= 19.31

Oracle Database Server 21.3 <= 21.22

Oracle Database Server 23.4.0 <= 23.26.2

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.