CVE-2026-60175

Oracle · Oracle Database Server

A vulnerability in the Oracle Database Server RDBMS component allows an authenticated user to perform a complete system takeover.

Executive summary

A critical vulnerability in Oracle Database Server enables authenticated users to gain full control of the RDBMS, creating a severe risk of database compromise.

Vulnerability

This vulnerability affects the RDBMS component and allows an authenticated user with network access via Oracle Net to compromise the database. Successful exploitation results in a full takeover of the database server.

Business impact

The CVSS score of 8.8 underscores the severity of this flaw. Unauthorized takeover of an RDBMS can lead to total data exfiltration, destruction of sensitive records, and a total loss of confidentiality, integrity, and availability for mission-critical business applications.

Remediation

Immediate Action: Deploy the July 2026 Oracle Critical Patch Update to all affected database environments.

Proactive Monitoring: Review database audit logs for suspicious administrative commands or unexpected privilege escalation by low-level user accounts.

Compensating Controls: Limit network access to the database listener and enforce the principle of least privilege for all database users to reduce the potential attack surface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Database administrators should prioritize this update immediately. Given the potential for total data loss, ensuring the RDBMS is patched is essential to protecting the organization's most critical information assets.