Vulnerability in Oracle Database Server RDBMS Component
CVE-2026-60175
8.8HIGH
What is CVE-2026-60175?
An exploitable vulnerability has been identified within the RDBMS component of Oracle Database Server, affecting versions 19.3-19.31, 21.3-21.22, and 23.4.0-23.26.2. This vulnerability allows a low privileged attacker with authenticated user privileges to access the network via Oracle Net, potentially leading to a complete takeover of the RDBMS. This security flaw poses significant risks to the affected database, jeopardizing its confidentiality, integrity, and availability.
Affected Version(s)
Oracle Database Server 19.3 <= 19.31
Oracle Database Server 21.3 <= 21.22
Oracle Database Server 23.4.0 <= 23.26.2