Vulnerability in Oracle Database Server's Portable Clusterware Component
CVE-2026-71102

9.1CRITICAL

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-71102?

A vulnerability has been identified in the Portable Clusterware component of Oracle Database Server, affecting multiple versions. This flaw allows an unauthenticated attacker with network access via HTTP to exploit the Portable Clusterware. Successful exploitation can lead to unauthorized actions, including the creation, deletion, or modification of critical data, as well as the potential for a denial-of-service condition by causing repeated crashes. Organizations using the affected versions are advised to review security practices and apply relevant updates to mitigate risks.

Affected Version(s)

Oracle Database Server 19.3 <= 19.32

Oracle Database Server 21.3 <= 21.23

Oracle Database Server 23.4.0 <= 23.26.3

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.