CVE-2026-83333
moderateUnauthenticated Denial-of-Service in Oracle Net Services (Oracle Database Server 23.x)
CVE-2026-83333 is a denial-of-service vulnerability in the Oracle Net Services component of Oracle Database Server, affecting supported versions 23.4.0 through 23.26.3. An unauthenticated attacker with network access to the Oracle Net listener can send specially crafted requests that are described by Oracle as 'easily exploitable,' causing the service to hang or crash repeatedly (a complete DoS). The flaw has no impact on confidentiality or integrity (CVSS 3.1: 7.5, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), but successful attacks take down database connectivity for dependent applications. Any organization running an affected 23.x Oracle Database release with a network-reachable TNS listener is exposed, with internet-facing listeners at greatest risk. The vulnerability is not on the CISA KEV list and no public proof-of-concept or observed exploitation is known at this time.
What to do: Apply the Oracle Critical Patch Update that remediates this flaw to all Oracle Database Server 23.4.0-23.26.3 instances, prioritizing any database whose TNS listener (typically TCP/1521) is reachable from untrusted networks. Restrict listener access with firewall rules and source allowlists so only application servers and DBA hosts can connect, and verify the listener is not exposed to the internet. Monitor for repeated TNS listener crashes or hangs, which would indicate exploitation attempts.
| Oracle Database Server (Oracle Net Services component) | 23.4.0 - 23.26.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Net Services. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Net Services. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
- Weakness
- CWE-400
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.