cve-2026-71062
HIGH CVSS 8.5 opencve
Description
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Difficult to exploit vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
Timeline
- Published
- 2026-08-18 21:18 UTC
- Last Modified
- 2026-08-20
CVSS Details
CVSS details not available.
Affected Products
No product information available.
CVSS metrics
| Version | Base | Severity | Vector | Exploitability | Impact | Source |
|---|---|---|---|---|---|---|
| 3.1 | 8.5 | HIGH | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
mitre | ||
| 3.1 | 8.5 | HIGH | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
nvd | ||
| 3.1 | 8.5 | HIGH | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
opencve |
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cve": "CVE-2026-71062",
"enrichment": {
"affected": [
{
"configurations": [
{
"platform": null,
"status": "affected",
"versions": {
"scheme": "generic",
"value": "[0,*]"
}
}
],
"enrichment": {
"confidence": 95.0,
"confidence_source": "inferred",
"scores": [
{
"score": 95.0,
"source": "inferred"
},
{
"score": 100.0,
"source": "matching"
}
]
},
"product": "database_-_rdbms",
"vendor": "oracle"
},
{
"configurations": [
{
"platform": null,
"status": "affected",
"versions": {
"scheme": "semver",
"value": "[23.4.0,23.26.3]"
}
}
],
"enrichment": {
"confidence": 95.0,
"confidence_source": "inferred",
"scores": [
{
"score": 95.0,
"source": "inferred"
},
{
"score": 100.0,
"source": "matching"
}
]
},
"original": {
"product": "Oracle Database Server",
"source": "cna",
"vendor": "Oracle Corporation"
},
"product": "database_server",
"vendor": "oracle"
}
],
"created": "2026-08-19T05:15:05.526802+00:00",
"title": "Privilege Escalation Enables Full Takeover of Oracle Database Server RDBMS",
"updated": "2026-08-20T19:30:05.407479+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$database_-_rdbms",
"oracle$PRODUCT$database_server"
]
},
"epss": {
"score": 0.00334
},
"mitre": {
"cpes": [
"cpe:2.3:a:oracle:database_-_rdbms:*:*:*:*:*:*:*:*"
],
"created": "2026-08-18T21:03:18.677000+00:00",
"description": "Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Difficult to exploit vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 8.5,
"vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
},
"cvssV4_0": {}
},
"mitre_repo_path": "cves/2026/71xxx/CVE-2026-71062.json",
"references": [
"https://www.oracle.com/security-alerts/cspuaug2026.html"
],
"title": null,
"updated": "2026-08-20T03:56:47.697000+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$database_-_rdbms"
],
"weaknesses": []
},
"nvd": {
"cpes": [
"cpe:2.3:a:oracle:database_server:*:*:*:*:*:*:*:*"
],
"created": "2026-08-18T21:18:06.080000+00:00",
"description": "Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Difficult to exploit vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 8.5,
"vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
},
"cvssV4_0": {}
},
"nvd_repo_path": "2026/CVE-2026-71062.json",
"references": [
"https://www.oracle.com/security-alerts/cspuaug2026.html"
],
"title": null,
"updated": "2026-08-20T15:09:41.410000+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$database_server"
],
"weaknesses": [
"CWE-284"
]
},
"opencve": {
"changes": [
{
"created": "2026-08-18T21:15:00+00:00",
"data": [
{
"details": {
"new": "Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Difficult to exploit vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
"old": null
},
"type": "description"
},
{
"details": [
"oracle",
"oracle$PRODUCT$database_-_rdbms"
],
"type": "first_time"
},
{
"details": {
"added": [
"cpe:2.3:a:oracle:database_-_rdbms:*:*:*:*:*:*:*:*"
],
"removed": []
},
"type": "cpes"
},
{
"details": {
"added": [
"oracle",
"oracle$PRODUCT$database_-_rdbms"
],
"removed": []
},
"type": "vendors"
},
{
"details": {
"added": [
"https://www.oracle.com/security-alerts/cspuaug2026.html"
],
"removed": []
},
"type": "references"
},
{
"details": {
"added": {
"cvssV3_1": {
"score": 8.5,
"vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "5b1fdc5d-be6f-4278-b8d7-a9265b26d610"
},
{
"created": "2026-08-19T05:30:00+00:00",
"data": [
{
"details": {
"new": "Authenticated User RDBMS Compromise via Oracle Net",
"old": null
},
"type": "title"
},
{
"details": {
"added": [
"CWE-284",
"CWE-306"
],
"removed": []
},
"type": "weaknesses"
}
],
"id": "f997dcff-94e2-4607-9ff1-bce035b9b14a"
},
{
"created": "2026-08-19T15:30:00+00:00",
"data": [
{
"details": {
"new": null,
"old": "Authenticated User RDBMS Compromise via Oracle Net"
},
"type": "title"
},
{
"details": {
"added": [],
"removed": [
"CWE-284",
"CWE-306"
]
},
"type": "weaknesses"
}
],
"id": "9c02179a-6b0a-4d56-bfa4-87cd1463e9cc"
},
{
"created": "2026-08-19T16:30:00+00:00",
"data": [
{
"details": {
"added": [
"CWE-284"
],
"removed": []
},
"type": "weaknesses"
}
],
"id": "682609d4-42af-4362-af2e-fb5b4dcec842"
},
{
"created": "2026-08-19T22:15:00+00:00",
"data": [
{
"details": {
"new": "Privilege Escalation Allowing RDBMS Takeover via Oracle Net",
"old": null
},
"type": "title"
}
],
"id": "27a17e4e-ba4a-4199-9570-7030ed9f9d17"
},
{
"created": "2026-08-20T02:00:00+00:00",
"data": [
{
"details": [
"oracle$PRODUCT$database_server"
],
"type": "first_time"
},
{
"details": {
"added": [
"oracle$PRODUCT$database_server"
],
"removed": []
},
"type": "vendors"
}
],
"id": "ca9bc4fe-2bb2-4c3e-a5cc-10e9ec5c46df"
},
{
"created": "2026-08-20T05:30:00+00:00",
"data": [
{
"details": {
"added": {
"ssvc": {
"options": {
"Automatable": "no",
"Exploitation": "none",
"Technical Impact": "total"
},
"version": "2.0.3"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "6d72a0eb-ab38-4422-a2b0-18e4de2979b8"
},
{
"created": "2026-08-20T06:45:00+00:00",
"data": [
{
"details": {
"new": null,
"old": "Privilege Escalation Allowing RDBMS Takeover via Oracle Net"
},
"type": "title"
}
],
"id": "27a978df-3c39-4a6b-afca-658752f7ebfc"
},
{
"created": "2026-08-20T15:15:00+00:00",
"data": [
{
"details": {
"added": [
"cpe:2.3:a:oracle:database_server:*:*:*:*:*:*:*:*"
],
"removed": []
},
"type": "cpes"
}
],
"id": "16561568-e14e-476d-a0d1-2ead222e1ae7"
},
{
"created": "2026-08-20T19:45:00+00:00",
"data": [
{
"details": {
"new": "Privilege Escalation Enables Full Takeover of Oracle Database Server RDBMS",
"old": null
},
"type": "title"
}
],
"id": "54f4b7ee-5563-456f-8387-faeba9b3370e"
}
],
"cpes": {
"data": [
"cpe:2.3:a:oracle:database_-_rdbms:*:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:database_server:*:*:*:*:*:*:*:*"
],
"providers": [
"mitre",
"nvd"
]
},
"created": {
"data": "2026-08-18T21:03:18.677000+00:00",
"provider": "mitre"
},
"description": {
"data": "Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Difficult to exploit vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
"provider": "mitre"
},
"metrics": {
"cvssV2_0": {
"data": {},
"provider": null
},
"cvssV3_0": {
"data": {},
"provider": null
},
"cvssV3_1": {
"data": {
"score": 8.5,
"vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
},
"provider": "mitre"
},
"cvssV4_0": {
"data": {},
"provider": null
},
"epss": {
"data": {
"score": 0.00334
},
"provider": "first"
},
"kev": {
"data": {},
"provider": null
},
"ssvc": {
"data": {
"options": {
"Automatable": "no",
"Exploitation": "none",
"Technical Impact": "total"
},
"version": "2.0.3"
},
"provider": "vulnrichment"
},
"threat_severity": {
"data": null,
"provider": null
}
},
"references": {
"data": [
"https://www.oracle.com/security-alerts/cspuaug2026.html"
],
"providers": [
"mitre",
"nvd"
]
},
"title": {
"data": "Privilege Escalation Enables Full Takeover of Oracle Database Server RDBMS",
"provider": "enrichment"
},
"updated": {
"data": "2026-08-20T19:30:05.407479+00:00",
"provider": "enrichment"
},
"vendors": {
"data": [
"oracle",
"oracle$PRODUCT$database_-_rdbms",
"oracle$PRODUCT$database_server"
],
"providers": [
"mitre",
"nvd",
"enrichment"
]
},
"weaknesses": {
"data": [
"CWE-284"
],
"providers": [
"nvd",
"vulnrichment"
]
}
},
"vulnrichment": {
"cpes": [],
"created": "2026-08-18T21:03:18.677000+00:00",
"description": "Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Difficult to exploit vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {},
"cvssV4_0": {},
"kev": {},
"ssvc": {
"options": {
"Automatable": "no",
"Exploitation": "none",
"Technical Impact": "total"
},
"version": "2.0.3"
}
},
"references": [],
"title": null,
"updated": "2026-08-19T15:47:41.833000+00:00",
"vendors": [],
"vulnrichment_repo_path": "2026/71xxx/CVE-2026-71062.json",
"weaknesses": [
"CWE-284"
]
}
}
Enrichment data
Aggregated bundle (all enrichments)