CVE-2026-83349
largeUnauthenticated Denial-of-Service in Oracle Net Services (Oracle Database Server)
CVE-2026-83349 is an easily exploitable vulnerability in the Oracle Net Services component of Oracle Database Server that allows an unauthenticated attacker with network access via Oracle Net (the TNS listener protocol, typically port 1521) to send crafted requests that cause the service to hang or crash repeatedly, resulting in complete denial of service. The flaw affects only availability — there is no impact on confidentiality or integrity of data (CVSS 3.1: 7.5, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Supported versions 19.3-19.32, 21.3-21.23, and 23.4.0-23.26.3 of Oracle Database Server are affected. Any organization running these releases with the TNS listener reachable by untrusted networks, particularly internet-facing listeners, is at risk of database connectivity outages. No public proof-of-concept is known, the issue is not in the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported as of this analysis.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83349 to all affected Database Server releases (19.x, 21.x, and 23.ai lines within the listed ranges) as soon as possible. Restrict network access to TNS listeners (ports 1521/1522) so only application servers and DBAs can reach them — internet-exposed listeners should be eliminated entirely, and listener.ora valid-node checking or IP allow-listing can further limit sources. Monitor for repeated listener crashes or hangs and unexpected connection storms on the listener port as indicators of attempted exploitation.
| Oracle Database Server (Oracle Net Services) | 19.3-19.32 |
| Oracle Database Server (Oracle Net Services) | 21.3-21.23 |
| Oracle Database Server (Oracle Net Services) | 23.4.0-23.26.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Net Services. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Net Services. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
- Weakness
- CWE-400
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.