
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-61211 is a critical improper access control vulnerability in the RDBMS component of Oracle Database Server, enabling a low-privileged attacker with the Execute DBMS_CLOUD privilege to achieve complete takeover of the database over the network. It affects Oracle Database Server versions 19.3–19.31 and 23.4.0–23.26.2. The vulnerability was disclosed on July 21, 2026, as part of Oracle's Critical Patch Update (CPU) for July 2026, and was reported by HexRabbit of DEVCORE Research Team. It carries a CVSS v3.1 base score of 9.9 (Critical) with a scope change, meaning successful exploitation can impact products beyond the database itself (Oracle CPU July 2026).
The vulnerability is classified as CWE-284 (Improper Access Control) within the RDBMS component of Oracle Database Server. An attacker with a low-privileged database account holding the Execute DBMS_CLOUD privilege can exploit this flaw remotely via Oracle Net without requiring user interaction or elevated complexity. The scope change (S:C in the CVSS vector) indicates that exploitation can affect resources beyond the vulnerable RDBMS component itself, potentially impacting additional Oracle products or services running in the same environment. No public proof-of-concept or detailed technical write-up has been disclosed as of the time of reporting (Oracle CPU July 2026).
Successful exploitation results in complete takeover of the Oracle RDBMS, with full compromise of confidentiality (unauthorized access to all database data), integrity (modification of database content), and availability (denial of service to the database). Due to the scope change, attacks may significantly impact additional products beyond the directly vulnerable RDBMS component, increasing the risk of lateral movement within Oracle environments. Organizations running Oracle Database Server in multi-tenant or enterprise environments face the highest exposure, as a single compromised low-privileged account with DBMS_CLOUD privileges could lead to enterprise-wide data breach (Oracle CPU July 2026).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The EPSS score is approximately 0.0045 (0.45%), reflecting a currently low but non-negligible probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability is considered "easily exploitable" by Oracle's own classification, requiring only a low-privileged account with the Execute DBMS_CLOUD privilege and network access via Oracle Net — no user interaction or high complexity is needed (Oracle CPU July 2026).
alert.log or unified audit trail.Oracle has released patches for this vulnerability as part of the July 2026 Critical Patch Update (CPU), published July 21, 2026. Affected versions are 19.3–19.31 and 23.4.0–23.26.2; administrators should apply the July 2026 CPU patches immediately. As interim workarounds, Oracle recommends: (1) restricting the Execute DBMS_CLOUD privilege to only trusted users who genuinely require it; (2) implementing network access controls (firewalls, Oracle Net valid node checking) to limit connectivity to the Oracle database over Oracle Net; and (3) reviewing and revoking unnecessary DBMS_CLOUD grants. Oracle strongly advises against relying on workarounds as a long-term solution, as they do not address the underlying vulnerability (Oracle CPU July 2026).
Oracle's July 2026 CPU was widely noted in the security community as a record-breaking update containing 1,449 patches, with CVE-2026-61211 highlighted as one of the most critical database vulnerabilities due to its 9.9 CVSS score and scope change. Coverage appeared across multiple outlets including The Register, CSO Online, InfoWorld, SOCRadar, and The Hacker News, primarily in the context of the overall scale of the July 2026 CPU rather than specific exploitation details for this CVE. HexRabbit of DEVCORE Research Team was credited by Oracle for discovering and reporting this vulnerability (Oracle CPU July 2026).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."