CVE-2026-47038: Low severity Oracle Oracle Database Server vulnerability
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows high privileged attacker having None privilege with network access via Oracle Net to compromise RDBMS. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of RDBMS accessible data. CVSS 3.1 Base Score 2.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47038?
The severity of CVE-2026-47038 is rated as low.
How do I fix CVE-2026-47038?
To fix CVE-2026-47038, update your Oracle Database Server to the latest patched version.
Which versions of Oracle Database Server are affected by CVE-2026-47038?
CVE-2026-47038 affects Oracle Database Server versions 19.3-19.31, 21.3-21.22, and 23.4.0-23.26.2.
What can an attacker do with CVE-2026-47038?
An attacker can exploit CVE-2026-47038 to compromise the RDBMS with high privileges if they have network access.
Is user interaction required to exploit CVE-2026-47038?
No, user interaction is not required to exploit CVE-2026-47038.