Vulnerability in Oracle Database Server's Portable Clusterware Component
CVE-2026-71064
9.6CRITICAL
What is CVE-2026-71064?
An unauthenticated attacker with physical access to the communication segments can exploit a vulnerability in the Portable Clusterware component of Oracle Database Server. This weakness spans several versions, including 19.3 to 19.32, 21.3 to 21.23, and 23.4.0 to 23.26.3, allowing for potential compromise of Portable Clusterware. While primarily affecting this component, the attack can cascade, impacting several interconnected products. Successful exploitation can lead to complete takeover of the Portable Clusterware, resulting in significant risks to data confidentiality, integrity, and availability.
Affected Version(s)
Oracle Database Server 19.3 <= 19.32
Oracle Database Server 21.3 <= 21.23
Oracle Database Server 23.4.0 <= 23.26.3