CVE-2026-46833: Critical severity Oracle Oracle Database Server vulnerability
Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service. While the vulnerability is in Net Service, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Net Service. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46833?
The severity of CVE-2026-46833 is classified as critical with a score of 9.
How do I fix CVE-2026-46833?
To fix CVE-2026-46833, apply the latest security patches provided by Oracle for the affected versions of the Oracle Database Server.
What types of attacks can exploit CVE-2026-46833?
CVE-2026-46833 can be exploited by an unauthenticated attacker with network access via TLS to compromise the Net Service component.
Which versions of Oracle Database Server are affected by CVE-2026-46833?
Affected versions of Oracle Database Server for CVE-2026-46833 are between 23.4.0 and 23.26.2.
How difficult is it to exploit CVE-2026-46833?
CVE-2026-46833 is classified as difficult to exploit, but attackers with the required network access can still pose a significant risk.