Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service. While the vulnerability is in Net Service, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Net Service. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspumay2026.html |
|
History
Thu, 28 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Network Service Takeover via TLS in Oracle Database Server | |
| Weaknesses | CWE-287 |
Thu, 28 May 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 May 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service. While the vulnerability is in Net Service, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Net Service. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H). | |
| First Time appeared |
Oracle
Oracle database - Net Service |
|
| CPEs | cpe:2.3:a:oracle:database_-_net_service:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle database - Net Service |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2026-05-28T20:47:29.685Z
Reserved: 2026-05-18T15:55:10.305Z
Link: CVE-2026-46833
Updated: 2026-05-28T20:47:26.327Z
Status : Received
Published: 2026-05-28T21:16:33.200
Modified: 2026-05-28T21:16:33.200
Link: CVE-2026-46833
No data.
OpenCVE Enrichment
Updated: 2026-05-28T21:30:26Z