Sceawere

Vulnerability Detail

CVE-2026-71102UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Database Portable Clusterware Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Database Server
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Portable Clusterware. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Portable Clusterware accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Portable Clusterware.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Portable Clusterware. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Portable Clusterware accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Portable Clusterware. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-08-18T21:18:10.493Z",
  "pubdate": "2026-08-18T21:18:10.493Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the Portable Clusterware component of Oracle Database Server, affecting supported versions 19.3-19.32, 21.3-21.23, and 23.4.0-23.26.3. This security flaw allows unauthenticated threat actors with network access via HTTP to directly compromise the targeted Portable Clusterware component without requiring user interaction.\nSuccessful exploitation of this vulnerability has severe operational implications, resulting in unauthorized creation, deletion, or modification capabilities affecting critical data as well as all data accessible to Portable Clusterware. Additionally, adversaries can induce a system hang or a frequently repeatable complete denial of service (DoS), severely destabilizing cluster operations.\nThe severity of this issue is underscored by a CVSS 3.1 Base Score of 9.1, driven by high impact ratings to both Integrity and Availability domains. The attack vector is fully network-based with low attack complexity, requiring zero privileges or user interaction under a scope-unchanged model. Organizations utilizing affected Oracle Database Server versions face significant operational and data integrity risks and must prioritize defensive planning and remediation.",
  "technicalDetails": "The vulnerability resides in the Portable Clusterware component of Oracle Database Server, specifically within routines handling incoming HTTP network traffic. The root cause stems from insufficient validation and improper handling of HTTP requests processed by the vulnerable component, enabling remote unauthenticated interactions to corrupt system state or disrupt service availability.\nExploitation is initiated over the network using the HTTP protocol. Because the attack vector is network-based (AV:N) with low attack complexity (AC:L) and requires no privileges (PR:N) or user interaction (UI:N), an unauthenticated remote attacker can directly transmit malicious HTTP payloads to the exposed service endpoints of Portable Clusterware.\nThe attack flow proceeds as follows: First, the adversary crafts specialized HTTP requests designed to target input validation weaknesses within the Portable Clusterware listening services. Second, the network service processes the unauthenticated payload without proper sanitization or authorization checks. Third, the malformed input triggers memory corruption, logic flaws, or resource exhaustion within the component.\nUpon successful processing of the payload, the post-exploitation impact manifests in two primary ways according to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H). Integrity (I:H) is heavily impacted, granting unauthorized attackers the capability to create, delete, or modify critical system data and any data accessible via Portable Clusterware. Availability (A:H) is similarly compromised, allowing the adversary to trigger an application hang or a frequently repeatable complete denial of service, forcing crashes of the Portable Clusterware infrastructure.\nThe affected product spans Oracle Database Server, specifically targeting the Portable Clusterware component across software version ranges 19.3-19.32, 21.3-21.23, and 23.4.0-23.26.3. No confidentiality impact is reported (C:N), but the combined loss of data integrity and availability presents a critical risk to enterprise database clusters."
}
CVE-2026-71102: Oracle Database Portable Clusterware Vulnerability (CRITICAL Severity, CVSS: 9.1) - Sceawere