Database Vulnerability in Oracle Database Server
CVE-2026-47038

2.7LOW

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-47038?

A security vulnerability exists in the RDBMS component of Oracle Database Server that enables attackers with high privileges to exploit it via Oracle Net. This flaw affects various supported versions, allowing unauthorized users to perform insert, update, or delete operations on accessible data within the database. The ease of exploitation highlights the need for immediate remediation steps to secure data integrity and prevent unauthorized actions.

Affected Version(s)

Oracle Database Server 19.3 <= 19.31

Oracle Database Server 21.3 <= 21.22

Oracle Database Server 23.4.0 <= 23.26.2

References

CVSS V3.1

Score:
2.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.