Oracle Database Server JDBC Component Vulnerability
CVE-2026-47060

6.5MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-47060?

A vulnerability exists in the JDBC component of Oracle Database Server that can be exploited by an unauthenticated attacker with network access via Oracle Net. Successful exploitation requires interaction from a third party, allowing attackers to leverage this vulnerability to compromise JDBC functions. This can lead to unauthorized creation, deletion, or modification of critical data accessible through JDBC, severely impacting data integrity.

Affected Version(s)

Oracle Database Server 19.3 <= 19.31

Oracle Database Server 21.3 <= 21.22

Oracle Database Server 23.4.0 <= 23.26.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.