
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-71063 is a critical improper access control vulnerability in the Portable Clusterware component of Oracle Database Server, allowing unauthenticated attackers with access to the physical communication segment to fully compromise the affected system. Affected versions include 19.3–19.32, 21.3–21.23, and 23.4.0–23.26.3. The vulnerability was disclosed and patched on August 18, 2026, as part of Oracle's Critical Security Patch Update (CSPU). It carries a CVSS v3.1 base score of 9.6 (Critical) (Oracle Advisory, NVD).
The vulnerability is classified as CWE-284 (Improper Access Control) and resides in Oracle's Portable Clusterware component, which manages cluster communication over TLS (NVD). An unauthenticated attacker positioned on the same physical network segment as the Portable Clusterware hardware can exploit this flaw without requiring any privileges or user interaction. The attack complexity is low, and the vulnerability exhibits a scope change, meaning successful exploitation can cascade to impact additional products beyond Portable Clusterware itself (Oracle Advisory). No public proof-of-concept or detailed technical write-up has been identified at this time (Feedly).
Successful exploitation results in a complete takeover of Portable Clusterware, with high impact to confidentiality, integrity, and availability. Because the vulnerability involves a scope change, connected Oracle products and cluster nodes may also be compromised, enabling potential lateral movement across the database cluster infrastructure. An attacker could exfiltrate sensitive database data, manipulate cluster operations, or cause denial of service across the affected cluster environment (Oracle Advisory, NVD).
As of the disclosure date, there is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). CISA's SSVC assessment classifies exploitation as "none" and the vulnerability as not automatable, reflecting the requirement for adjacent network access (NVD). The EPSS score is approximately 0.0026 (0.26%), indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
Oracle has released patches for all affected versions as part of the August 18, 2026 Critical Security Patch Update (CSPU); organizations should apply the relevant patch for their version (19.3–19.32, 21.3–21.23, or 23.4.0–23.26.3) immediately (Oracle Advisory). As a temporary workaround, restrict physical and logical access to the network segments used by Portable Clusterware, and implement network segmentation to isolate Portable Clusterware infrastructure from untrusted hosts. Oracle strongly recommends against relying on network-level mitigations as a long-term solution, as they do not address the underlying vulnerability.
Oracle's August 2026 CSPU was noted by security vendors as a large release containing 943 new security patches across product families, with CVE-2026-71063 highlighted as one of the highest-severity Database Server vulnerabilities (Waratek). The vulnerability was picked up by vulnerability tracking platforms including VulDB and AUSCERT shortly after disclosure (AUSCERT). No significant independent researcher commentary or social media discussion specific to this CVE has been identified beyond standard advisory aggregation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."