Vulnerability in Portable Clusterware Component of Oracle Database Server
CVE-2026-71063

9.6CRITICAL

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-71063?

A vulnerability exists in the Portable Clusterware component of Oracle Database Server, affecting multiple versions. This issue enables unauthorized attackers with physical access to compromise the Portable Clusterware. Although the vulnerability is contained within Portable Clusterware, successful exploitation can have broader implications, impacting the integrity and availability of associated Oracle products. Attackers can potentially take over the Portable Clusterware, leading to significant security risks.

Affected Version(s)

Oracle Database Server 19.3 <= 19.32

Oracle Database Server 21.3 <= 21.23

Oracle Database Server 23.4.0 <= 23.26.3

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.