Vulnerability in Java VM Component of Oracle Database Server
CVE-2026-47039

6.5MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-47039?

A vulnerability exists in the Java VM component of Oracle Database Server, potentially allowing low-privileged attackers with Create Session privileges and network access via Oracle Net to compromise the Java VM. Exploiting this vulnerability can lead to unauthorized creation, deletion, or modification of critical data and all data accessible through the Java VM. Affected versions include 19.3 to 19.31, 21.3 to 21.22, and others. It is crucial for users to apply the necessary patches to safeguard their data integrity and security.

Affected Version(s)

Oracle Database Server 19.3 <= 19.31

Oracle Database Server 21.3 <= 21.22

Oracle Database Server 23.4.0 <= 23.26.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.