CVE-2026-23927: Agent 2 Oracle plugin TNS connection string injection via the 'service' parameter
A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an attacker-controlled server and leaking Oracle database credentials if they are saved in a named session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23927?
The severity of CVE-2026-23927 is defined as critical due to the potential for sensitive data leakage from the Oracle database.
How do I fix CVE-2026-23927?
To fix CVE-2026-23927, ensure to validate and sanitize all user inputs in the 'service' parameter to prevent injection vulnerabilities.
What are the potential impacts of CVE-2026-23927?
The potential impacts of CVE-2026-23927 include unauthorized access to Oracle database credentials and connections to malicious servers.
Which software is affected by CVE-2026-23927?
CVE-2026-23927 affects the Agent 2 Oracle plugin.
Who can exploit CVE-2026-23927?
An attacker with the ability to connect to Agent 2 can exploit CVE-2026-23927 through injecting an Oracle TNS connection string.