
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-71064 is a critical vulnerability in the Portable Clusterware component of Oracle Database Server that allows unauthenticated attackers with access to the physical communication segment to fully compromise the affected component. Affected versions include Oracle Database Server 19.3–19.32, 21.3–21.23, and 23.4.0–23.26.3. The vulnerability was disclosed and patched on August 18, 2026, as part of Oracle's Critical Security Patch Update (CSPU) for August 2026. It carries a CVSS v3.1 base score of 9.6 (Critical), reflecting high impacts across confidentiality, integrity, and availability with a scope change (Oracle Advisory, NVD).
The vulnerability resides in the Portable Clusterware component of Oracle Database Server and is classified as NVD-CWE-noinfo (Insufficient Information), meaning Oracle has not publicly disclosed the precise root cause. Exploitation occurs over the adjacent network (physical communication segment) using the TLS protocol, requiring no authentication, no user interaction, and low attack complexity. The attack vector is constrained to the local network segment attached to the hardware running Portable Clusterware, but a successful exploit results in a scope change — meaning impacts can extend beyond the directly vulnerable component to additional Oracle Database products (Oracle Advisory, NVD).
Successful exploitation results in complete takeover of the Portable Clusterware component, with high impacts on confidentiality, integrity, and availability. Because the vulnerability triggers a scope change, attacks may significantly affect additional Oracle Database products beyond Portable Clusterware itself, potentially enabling lateral movement within the database cluster environment. This could expose sensitive database contents, allow unauthorized modification of cluster configurations or data, and disrupt availability of clustered database services (Oracle Advisory, NVD).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.257%, indicating a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. Detection coverage is available via Qualys (detection ID 20609) and Tenable (Nessus plugin 338071).
Oracle has released patches for all affected versions (19.3–19.32, 21.3–21.23, 23.4.0–23.26.3) as part of the August 2026 Critical Security Patch Update, available via My Oracle Support. Oracle strongly recommends applying the patch immediately. As a temporary workaround, organizations should implement strict network segmentation to restrict access to the physical communication segment where Portable Clusterware executes, and enforce access controls to limit adjacency to trusted hosts only. Systems that cannot be patched immediately should be isolated until patching is feasible (Oracle Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."