
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-46834 is a Denial of Service vulnerability in the Net Service component of Oracle Database Server, classified under CWE-400 (Uncontrolled Resource Consumption). It affects supported versions 23.4.0 through 23.26.2 and allows an unauthenticated attacker with network access via TLS to cause a hang or frequently repeatable crash of the Net Service component. The vulnerability was disclosed on May 28, 2026, as part of Oracle's May 2026 Critical Security Patch Update (CSPU). It carries a CVSS v3.1 base score of 7.5 (High) (Oracle Advisory, GitHub Advisory).
The root cause is uncontrolled resource consumption (CWE-400) in Oracle Database Server's Net Service component, which handles TLS-based network communications. An unauthenticated remote attacker can send specially crafted TLS requests that cause the Net Service to exhaust resources, resulting in a hang or crash. No privileges or user interaction are required, and the attack complexity is low, making this easily exploitable over any network-accessible Oracle Database instance running a 23.x Oracle Home (including Database, Grid, and Client installations). The vulnerability also affects client-only installations of Oracle Database Server (Oracle Advisory). No public proof-of-concept or detailed technical write-up has been identified at this time (GitHub Advisory).
Successful exploitation results in a complete denial of service of the Oracle Database Net Service — the component responsible for managing network connections to the database. An attacker can repeatedly trigger hangs or crashes, rendering the database inaccessible to legitimate users and applications. There is no confidentiality or integrity impact; the vulnerability is limited to availability. Notably, databases running earlier Oracle Database versions are also vulnerable if they operate under a 23.x Grid infrastructure that has not been patched (Oracle Advisory).
Oracle has released patches for CVE-2026-46834 as part of the May 2026 Critical Security Patch Update. Patches must be applied to all 23.x Oracle Homes, including Database, Grid, and Client installations. As a temporary workaround, Oracle recommends blocking network access to the TLS-based Net Service port (typically TCP 1521 or configured listener port) from untrusted sources, though this may disrupt application connectivity. Oracle strongly advises against treating network blocking as a long-term solution and recommends applying the security patch as soon as possible (Oracle Advisory).
The vulnerability was covered in security news outlets including CyberSecurityNews and CyberNoz in the context of Oracle's broader May 2026 CSPU, which addressed 35 vulnerabilities across multiple product families. No notable individual researcher commentary or significant social media discussion specific to CVE-2026-46834 has been identified, likely due to the absence of a public PoC and its DoS-only impact (Oracle Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."