Vulnerability in Oracle Database Server's Portable Clusterware Component
CVE-2026-71064

9.6CRITICAL

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-71064?

An unauthenticated attacker with physical access to the communication segments can exploit a vulnerability in the Portable Clusterware component of Oracle Database Server. This weakness spans several versions, including 19.3 to 19.32, 21.3 to 21.23, and 23.4.0 to 23.26.3, allowing for potential compromise of Portable Clusterware. While primarily affecting this component, the attack can cascade, impacting several interconnected products. Successful exploitation can lead to complete takeover of the Portable Clusterware, resulting in significant risks to data confidentiality, integrity, and availability.

Affected Version(s)

Oracle Database Server 19.3 <= 19.32

Oracle Database Server 21.3 <= 21.23

Oracle Database Server 23.4.0 <= 23.26.3

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.