---
id: CVE-2026-71064
title: Vulnerability in the Portable Clusterware component of Oracle Database Server
summary: >-
  Vulnerability in the Portable Clusterware component of Oracle Database
  Server.  Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 
  23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated
  attacker with ac…
severity: critical
cvss: 9.6
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-284
vendor: oracle
product: database_server
affected:
  - 'database_server >= 19.3, <= 19.32'
  - 'database_server >= 21.3, <= 21.23'
  - 'database_server >= 23.4.0, <= 23.26.3'
published: '2026-08-18'
updated: '2026-08-22'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-71064'
references:
  - url: 'https://www.oracle.com/security-alerts/cspuaug2026.html'
    label: secalert_us@oracle.com
tags:
  - nvd
epss: 0.00335
epssPercentile: 0.26947
ingestedAt: '2026-08-22T21:37:49.707Z'
---

## Overview

Vulnerability in the Portable Clusterware component of Oracle Database Server.  Supported versions that are affected are 19.3-19.32, 21.3-21.23 and  23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Portable Clusterware executes to compromise Portable Clusterware.  While the vulnerability is in Portable Clusterware, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Portable Clusterware. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

## Affected

- `database_server >= 19.3, <= 19.32`
- `database_server >= 21.3, <= 21.23`
- `database_server >= 23.4.0, <= 23.26.3`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
