CVE-2026-46833
Oracle Database Server vulnerability analysis and mitigation

Overview

CVE-2026-46833 is a critical vulnerability in the Net Service component of Oracle Database Server that allows unauthenticated remote attackers to compromise the service via TLS, potentially resulting in a full takeover. It affects Oracle Database Server versions 23.4.0 through 23.26.2, including client-only installations. The vulnerability was disclosed on May 28, 2026, as part of Oracle's May 2026 Critical Security Patch Update (CSPU), and was reported by HexRabbit of DEVCORE Research Team. It carries a CVSS v3.1 base score of 9.0 (Critical) with a scope change, meaning successful exploitation can impact products beyond Net Service itself (Oracle CSPU May 2026, GitHub Advisory).

Technical details

The vulnerability resides in the Net Service component of Oracle Database Server and is exploitable over the network via TLS without requiring authentication or user interaction. The attack complexity is rated High, indicating that exploitation requires specific conditions or advanced techniques to be met, though no privileges are needed. The vulnerability carries a scope change (S:C), meaning a successful attack can affect components or resources beyond the vulnerable Net Service itself — potentially impacting other Oracle products running in the same environment. Oracle has not publicly disclosed the precise root cause or technical mechanism, but the attack vector via TLS suggests a flaw in the handling of TLS connections within the Net service layer. The vulnerability also affects client-only Oracle 23.x installations, and databases running earlier versions are vulnerable if operating under a 23.x Grid that has not been patched (Oracle CSPU May 2026, GitHub Advisory).

Impact

Successful exploitation can result in a complete takeover of the Oracle Database Net Service, with high impacts to confidentiality, integrity, and availability. An unauthenticated attacker with network access via TLS could gain full read/write access to data managed by the service and disrupt its availability. Due to the scope change, the attack may extend beyond Net Service to affect additional Oracle products or components sharing the same environment, increasing the risk of lateral movement and broader infrastructure compromise (Oracle CSPU May 2026, Feedly).

Mitigation and workarounds

Oracle has released patches for CVE-2026-46833 as part of the May 2026 Critical Security Patch Update. Patches must be applied to all 23.x Oracle Homes, including Database, Grid, and Client installations. Databases running earlier versions are also vulnerable if operating under an unpatched 23.x Grid. As a temporary workaround, Oracle recommends blocking network protocols required by the attack (i.e., restricting TLS access to Oracle Net Service from untrusted networks), though this may impact application functionality and is not a long-term solution. Organizations should also implement TLS certificate pinning and monitor for suspicious TLS connections to Net Service components (Oracle CSPU May 2026).

Community reactions

Oracle's May 2026 CSPU received broad coverage from security news outlets including Heise, CyberSecurityNews, and SecurityOnline, which highlighted the 35 vulnerabilities addressed in the update, with CVE-2026-46833 noted as one of the most critical (Heise, CyberSecurityNews). The Hacker Wire published a dedicated article on CVE-2026-46833, describing it as a critical Net Service takeover vulnerability (The Hacker Wire). Singapore's Cyber Security Agency (CSA) issued an advisory referencing the Oracle May 2026 CSPU, indicating government-level attention to the patch release (CSA Advisory). Community discussion on Bluesky and threat intelligence platforms noted the vulnerability's high CVSS score and scope change as key risk factors.

Additional resources


SourceThis report was generated using AI

Related Oracle Database Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-46833CRITICAL9
  • Oracle Database Server logoOracle Database Server
  • cpe:2.3:a:oracle:database_server
NoNoMay 28, 2026
CVE-2026-46835HIGH7.5
  • Oracle Database Server logoOracle Database Server
  • cpe:2.3:a:oracle:database_server
NoNoMay 28, 2026
CVE-2026-46834HIGH7.5
  • Oracle Database Server logoOracle Database Server
  • cpe:2.3:a:oracle:database_server
NoNoMay 28, 2026
CVE-2026-21939HIGH7
  • Oracle Database Server logoOracle Database Server
  • cpe:2.3:a:oracle:database_server
NoNoJan 20, 2026
CVE-2026-34312LOW2.4
  • Oracle Database Server logoOracle Database Server
  • cpe:2.3:a:oracle:database_server
NoNoApr 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management