CVE-2026-35229

7.5

Oracle · Database Server

An unauthenticated vulnerability exists in the Java VM component of Oracle Database Server that allows remote attackers to compromise the component via Oracle Net.

Executive summary

A critical vulnerability in the Oracle Database Server Java VM component allows unauthenticated attackers to gain unauthorized access to sensitive data via network exploitation.

Vulnerability

This vulnerability affects the Java VM component and is accessible to unauthenticated attackers over the network using the Oracle Net protocol. The flaw allows for unauthorized access to critical data or complete access to all data accessible by the Java VM.

Business impact

The ability for an unauthenticated remote attacker to access sensitive information stored within the Java VM environment poses a significant threat to data confidentiality. Given the CVSS score of 7.5, this high severity flaw could lead to extensive data breaches, regulatory non-compliance, and loss of intellectual property if left unpatched.

Remediation

Immediate Action: Apply the vendor security updates provided in the April 2026 Critical Patch Update (CPU) to all affected Oracle Database Server instances.

Proactive Monitoring: Monitor network traffic for unusual activity originating from the Oracle Net protocol and review database audit logs for unauthorized access attempts or suspicious Java VM executions.

Compensating Controls: Implement network segmentation to restrict access to the database server to known, trusted hosts and utilize a Web Application Firewall or database firewall to filter malicious traffic patterns targeting the Oracle Net listener.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The exposure of the Java VM component to unauthenticated network access represents a high risk to organizational data integrity. Administrators must prioritize the application of the April 2026 security patches provided by Oracle to remediate this flaw. Failure to act promptly could allow an attacker to bypass standard security controls and exfiltrate sensitive data directly from the database environment.

More Oracle CVEs

Sources