Unauthenticated Access Vulnerability in Oracle Database Server
CVE-2026-71100

5.3MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-71100?

The vulnerability affects the RDBMS component of Oracle Database Server, allowing unauthenticated attackers with network access via Oracle Net to exploit it. This can lead to unauthorized read access to sensitive data within the database. The affected versions include 19.3-19.32, 21.3-21.23, and 23.4.0-23.26.3, presenting a serious risk for applications relying on these database versions.

Affected Version(s)

Oracle Database Server 19.3 <= 19.32

Oracle Database Server 21.3 <= 21.23

Oracle Database Server 23.4.0 <= 23.26.3

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.