ZeroHour

CVE-2026-83333

moderate

Unauthenticated Denial-of-Service in Oracle Net Services (Oracle Database Server 23.x)

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83333 is a denial-of-service vulnerability in the Oracle Net Services component of Oracle Database Server, affecting supported versions 23.4.0 through 23.26.3. An unauthenticated attacker with network access to the Oracle Net listener can send specially crafted requests that are described by Oracle as 'easily exploitable,' causing the service to hang or crash repeatedly (a complete DoS). The flaw has no impact on confidentiality or integrity (CVSS 3.1: 7.5, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), but successful attacks take down database connectivity for dependent applications. Any organization running an affected 23.x Oracle Database release with a network-reachable TNS listener is exposed, with internet-facing listeners at greatest risk. The vulnerability is not on the CISA KEV list and no public proof-of-concept or observed exploitation is known at this time.

What to do: Apply the Oracle Critical Patch Update that remediates this flaw to all Oracle Database Server 23.4.0-23.26.3 instances, prioritizing any database whose TNS listener (typically TCP/1521) is reachable from untrusted networks. Restrict listener access with firewall rules and source allowlists so only application servers and DBA hosts can connect, and verify the listener is not exposed to the internet. Monitor for repeated TNS listener crashes or hangs, which would indicate exploitation attempts.

Affected
Oracle Database Server (Oracle Net Services component)23.4.0 - 23.26.3
Estimated exposure
moderatelikely a few thousand internet-exposed 23.x TNS listeners (subset of the roughly tens of thousands of exposed Oracle listeners seen in public scans) — Public internet scans (e.g., Shodan/FOFA) have historically shown on the order of 30,000-40,000 Oracle TNS listener endpoints exposed, but the vulnerable 23.x (23ai) release family is relatively new and represents only a fraction of that…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Net Services. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Net Services. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.