CVE-2026-34312
Oracle Database Server vulnerability analysis and mitigation

Overview

CVE-2026-34312 is an improper access control vulnerability in the RDBMS component of Oracle Database Server, classified as an authorization bypass. It affects supported versions 19.3 through 19.30 and was disclosed on April 21, 2026, as part of Oracle's April 2026 Critical Patch Update (CPU). The vulnerability carries a CVSS v3.1 base score of 2.4 (Low severity) (Oracle CPU Apr 2026, Github Advisory). The vulnerability was reported to Oracle by Aleksei Veremeev of a2.solutions (Oracle CPU Apr 2026).

Technical details

The vulnerability is rooted in improper access control (CWE-284) within the RDBMS component of Oracle Database Server. An attacker with the Row Access Method privilege can exploit this flaw over a network using multiple protocols to gain unauthorized read access to a subset of RDBMS-accessible data. Exploitation requires human interaction from a person other than the attacker, and the attack complexity is low once the required privilege is held. No detailed technical write-up or proof-of-concept code has been publicly disclosed (Oracle CPU Apr 2026, Github Advisory).

Impact

Successful exploitation results solely in a confidentiality impact — specifically, unauthorized read access to a subset of data accessible within the RDBMS. There is no impact on data integrity or system availability. The scope of the vulnerability is unchanged, meaning the impact is confined to the Oracle Database Server component itself, with no evidence of lateral movement potential or broader system compromise (Oracle CPU Apr 2026).

Mitigation and workarounds

Oracle has released a patch for this vulnerability as part of the April 2026 Critical Patch Update. Administrators running Oracle Database Server versions 19.3 through 19.30 should apply the CPU patch immediately. As a temporary workaround, Oracle recommends restricting the Row Access Method privilege to only those users who genuinely require it, and implementing network segmentation to limit database access to authorized users. Oracle strongly advises against relying on workarounds as a long-term solution (Oracle CPU Apr 2026).

Additional resources


SourceThis report was generated using AI

Related Oracle Database Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-46833CRITICAL9
  • Oracle Database Server logoOracle Database Server
  • cpe:2.3:a:oracle:database_server
NoNoMay 28, 2026
CVE-2026-46835HIGH7.5
  • Oracle Database Server logoOracle Database Server
  • cpe:2.3:a:oracle:database_server
NoNoMay 28, 2026
CVE-2026-46834HIGH7.5
  • Oracle Database Server logoOracle Database Server
  • cpe:2.3:a:oracle:database_server
NoNoMay 28, 2026
CVE-2026-21939HIGH7
  • Oracle Database Server logoOracle Database Server
  • cpe:2.3:a:oracle:database_server
NoNoJan 20, 2026
CVE-2026-34312LOW2.4
  • Oracle Database Server logoOracle Database Server
  • cpe:2.3:a:oracle:database_server
NoNoApr 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management