ZeroHour

CVE-2026-83350

large

Unauthenticated Denial-of-Service in Oracle Net Services for Oracle Database Server

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83350 is an easily exploitable flaw in the Oracle Net Services component of Oracle Database Server, affecting supported releases 21.3-21.23 and 23.4.0-23.26.3. An unauthenticated attacker who can reach the database over the network via Oracle Net (typically the TNS listener on port 1521) can send crafted requests that cause the service to hang or crash repeatedly, resulting in a complete denial of service. There is no impact on confidentiality or integrity, but availability of the database listener is fully compromised. Any organization running the affected 21c or 23ai Database Server releases with Oracle Net reachable by untrusted parties is at risk. No public proof-of-concept is known and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog.

What to do: Apply the Oracle Critical Patch Update that remediates this flaw and move to a Database Server version outside the affected ranges (21.3-21.23 and 23.4.0-23.26.3). Restrict network access to Oracle Net listeners (default port 1521) so only trusted application servers and admins can connect, and enable valid-node checking at the listener. Watch for unexplained listener hangs or repeated crashes as an indicator of attempted exploitation.

Affected
Oracle Database Server (Oracle Net Services component)21.3-21.23
Oracle Database Server (Oracle Net Services component)23.4.0-23.26.3
Estimated exposure
large≈30,000-50,000 internet-exposed Oracle TNS listeners (public scan data), plus a larger population of internal instances — Public internet scan services (Shodan/Censys) have historically shown tens of thousands of Oracle TNS listeners on port 1521 exposed to the internet, while Oracle Database is deployed at a large share of mid-to-large enterprises, most of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Net Services. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Net Services. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.