Boletines de Vulnerabilidades |
CVE-2026-23927 |
|
| Software afectado | ORACLE |
| A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an attacker-controlled server and leaking Oracle database credentials if they are saved in a named session. | |
Link: |
|
| https://nvd.nist.gov/vuln/detail/CVE-2026-23927 | |














