CVE-2026-47061: Medium severity Oracle Oracle Database Server (JDBC) vulnerability
Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the JDBC executes to compromise JDBC. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JDBC, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all JDBC accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to the physical communication segment used by the Oracle Database Server JDBC component (e.g., segment the network and limit connectivity to trusted hosts/users) to mitigate exploitation by an unauthenticated attacker with physical-segment access.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47061?
The severity of CVE-2026-47061 is medium with a score of 5.6.
How do I fix CVE-2026-47061?
To fix CVE-2026-47061, upgrade to a supported version of Oracle Database Server that is not affected.
Which versions of Oracle Database Server are affected by CVE-2026-47061?
Affected versions include Oracle Database Server 19.3-19.31, 21.3-21.22, and 23.4.0-23.26.2.
What attack vector is involved in CVE-2026-47061?
CVE-2026-47061 allows unauthenticated attackers to exploit the vulnerability if they have access to the physical communication segment of the hardware.
What type of vulnerability is CVE-2026-47061?
CVE-2026-47061 is identified as a difficult to exploit vulnerability in the JDBC component of the Oracle Database Server.