CVE-2026-46834
Oracle Database Server vulnerability analysis and mitigation

Overview

CVE-2026-46834 is a Denial of Service vulnerability in the Net Service component of Oracle Database Server, classified under CWE-400 (Uncontrolled Resource Consumption). It affects supported versions 23.4.0 through 23.26.2 and allows an unauthenticated attacker with network access via TLS to cause a hang or frequently repeatable crash of the Net Service component. The vulnerability was disclosed on May 28, 2026, as part of Oracle's May 2026 Critical Security Patch Update (CSPU). It carries a CVSS v3.1 base score of 7.5 (High) (Oracle Advisory, GitHub Advisory).

Technical details

The root cause is uncontrolled resource consumption (CWE-400) in Oracle Database Server's Net Service component, which handles TLS-based network communications. An unauthenticated remote attacker can send specially crafted TLS requests that cause the Net Service to exhaust resources, resulting in a hang or crash. No privileges or user interaction are required, and the attack complexity is low, making this easily exploitable over any network-accessible Oracle Database instance running a 23.x Oracle Home (including Database, Grid, and Client installations). The vulnerability also affects client-only installations of Oracle Database Server (Oracle Advisory). No public proof-of-concept or detailed technical write-up has been identified at this time (GitHub Advisory).

Impact

Successful exploitation results in a complete denial of service of the Oracle Database Net Service — the component responsible for managing network connections to the database. An attacker can repeatedly trigger hangs or crashes, rendering the database inaccessible to legitimate users and applications. There is no confidentiality or integrity impact; the vulnerability is limited to availability. Notably, databases running earlier Oracle Database versions are also vulnerable if they operate under a 23.x Grid infrastructure that has not been patched (Oracle Advisory).

Mitigation and workarounds

Oracle has released patches for CVE-2026-46834 as part of the May 2026 Critical Security Patch Update. Patches must be applied to all 23.x Oracle Homes, including Database, Grid, and Client installations. As a temporary workaround, Oracle recommends blocking network access to the TLS-based Net Service port (typically TCP 1521 or configured listener port) from untrusted sources, though this may disrupt application connectivity. Oracle strongly advises against treating network blocking as a long-term solution and recommends applying the security patch as soon as possible (Oracle Advisory).

Community reactions

The vulnerability was covered in security news outlets including CyberSecurityNews and CyberNoz in the context of Oracle's broader May 2026 CSPU, which addressed 35 vulnerabilities across multiple product families. No notable individual researcher commentary or significant social media discussion specific to CVE-2026-46834 has been identified, likely due to the absence of a public PoC and its DoS-only impact (Oracle Advisory).

Additional resources


SourceThis report was generated using AI

Related Oracle Database Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-46833CRITICAL9
  • Oracle Database Server logoOracle Database Server
  • cpe:2.3:a:oracle:database_server
NoNoMay 28, 2026
CVE-2026-46835HIGH7.5
  • Oracle Database Server logoOracle Database Server
  • cpe:2.3:a:oracle:database_server
NoNoMay 28, 2026
CVE-2026-46834HIGH7.5
  • Oracle Database Server logoOracle Database Server
  • cpe:2.3:a:oracle:database_server
NoNoMay 28, 2026
CVE-2026-21939HIGH7
  • Oracle Database Server logoOracle Database Server
  • cpe:2.3:a:oracle:database_server
NoNoJan 20, 2026
CVE-2026-34312LOW2.4
  • Oracle Database Server logoOracle Database Server
  • cpe:2.3:a:oracle:database_server
NoNoApr 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management