CVEFinder.io

CVE-2026-46833

⛔ critical
🔍 Scan for this CVE
Summary

Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service. While the vulnerability is in Net Service, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Net Service. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and

Description

Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service. While the vulnerability is in Net Service, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Net Service. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).

CVSS Score
9.0
Critical
EPSS Score
0.3
Exploit Probability
Published Date
2026-05-28
First Seen: 2026-05-29
📊 Relative Risk Intelligence

This CVE is High Risk - more severe than 87.7% of all 338,292 vulnerabilities in our database.

#41,591
Top 25% most severe
Severity Percentile
đŸŽ¯ CISA SSVC Assessment Updated: May 28, 2026
🔍 Exploitation Status
None
No known exploits
âš™ī¸ Automatable
YES
Can be exploited automatically
đŸ’Ĩ Technical Impact
Total
Complete system compromise possible
SSVC data provided by CISA
Last Modified 2026-07-21
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

đŸ“Ļ Affected Products 1

🔗 References 1

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-46834 âš ī¸ high 7.5 0.3 Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-2... 2026-05-28
CVE-2026-46835 âš ī¸ high 7.5 0.3 Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-2... 2026-05-28
CVE-2026-34312 â„šī¸ low 2.4 0.0 Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.30. Ea... 2026-04-21
CVE-2026-21939 âš ī¸ high 7.0 0.0 Vulnerability in the SQLcl component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.0... 2026-01-20
CVE-2025-53047 đŸ”ļ medium 5.8 0.0 Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are... 2025-10-21
CVE-2025-53051 â„šī¸ low 2.7 0.0 Vulnerability in the RDBMS Functional Index component of Oracle Database Server. Supported versions that are affected a... 2025-10-21
These CVEs affect the same products