
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-71062 is an Improper Access Control vulnerability (CWE-284) in the RDBMS component of Oracle Database Server, allowing a low-privileged authenticated attacker to achieve full takeover of the RDBMS via Oracle Net. Affected versions are 23.4.0 through 23.26.3; earlier major versions (19.x, 21.x) are not listed as affected for this specific CVE. The vulnerability was disclosed on August 18, 2026, as part of Oracle's August 2026 Critical Security Patch Update (CSPU). It carries a CVSS v3.1 base score of 8.5 (High), with a scope change indicating potential impact on additional products beyond the RDBMS itself (Oracle Advisory, NVD).
The vulnerability is classified as CWE-284 (Improper Access Control) within the RDBMS component of Oracle Database Server. An attacker with low-level authenticated user privileges can exploit this flaw over a network connection using the Oracle Net protocol, without requiring any user interaction. Exploitation is rated as "difficult" (High Attack Complexity), suggesting specific conditions or timing must be met, but successful exploitation results in a complete scope change — meaning impacts can extend beyond the directly targeted RDBMS to additional products or components. The vulnerability was reported to Oracle by Hugo Leclercq and Patrick Ventuzelo (Oracle Advisory).
Successful exploitation of CVE-2026-71062 results in a full takeover of the Oracle RDBMS, with high impacts to confidentiality, integrity, and availability. An attacker can read sensitive database contents, modify or delete data, and disrupt database availability. Due to the scope change in the CVSS rating, the attack may also significantly impact additional products or services that depend on the compromised database instance, increasing the risk of lateral movement within an enterprise environment (Oracle Advisory, NVD).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation. CISA's SSVC assessment classifies exploitation as "none" and the vulnerability as not automatable, reflecting the high attack complexity requirement. The EPSS score is approximately 0.0027 (0.27%), indicating a low near-term probability of exploitation. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (NVD, Oracle Advisory).
Oracle has released a patch for CVE-2026-71062 as part of the August 2026 Critical Security Patch Update (CSPU), published on August 18, 2026. Organizations running Oracle Database Server versions 23.4.0 through 23.26.3 should apply the patch immediately. As interim mitigations, Oracle recommends restricting network access to Oracle Net services to only trusted users and systems, implementing network segmentation to limit connectivity to the database server, and enforcing the principle of least privilege for database user accounts. Oracle strongly advises against relying solely on network-level workarounds as a long-term solution (Oracle Advisory).
The vulnerability was covered in the context of Oracle's broader August 2026 CSPU, which included 943 security patches across product families. GBHackers reported on the scale of the Oracle patch release, noting the large number of fixes. No specific researcher commentary or significant social media discussion focused exclusively on CVE-2026-71062 has been identified beyond the standard patch advisory coverage (Oracle Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."