CVE-2026-83160
8.8Oracle · Database Server
A vulnerability in the RDBMS component of Oracle Database Server allows a low privileged attacker to achieve a full system takeover via Oracle Net.
Executive summary
A high severity vulnerability in Oracle Database Server versions 23.4.0 through 23.26.3 enables authenticated attackers with minimal privileges to fully compromise the database system.
Vulnerability
This vulnerability exists within the RDBMS component and is accessible via Oracle Net. It allows an attacker with low privileges, specifically those holding the Create Table privilege, to execute a successful attack resulting in a complete takeover of the RDBMS.
Business impact
Successful exploitation of this flaw grants an attacker full control over the database environment, leading to a complete compromise of confidentiality, integrity, and availability. Given the CVSS 3.1 base score of 8.8, this represents a significant risk to organizational data, potentially exposing sensitive information and causing severe operational disruption.
Remediation
Immediate Action: Review official Oracle security alerts for the September 2026 cycle and apply the designated patch as soon as it becomes available for your specific environment.
Proactive Monitoring: Monitor Oracle Net traffic for unusual administrative commands or unauthorized attempts to utilize the Create Table privilege by low privileged accounts.
Compensating Controls: Restrict network access to the database server to known, trusted IP addresses and strictly audit the assignment of the Create Table privilege to minimize the attack surface.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The potential for a complete takeover of the Oracle Database Server necessitates immediate attention from database administrators. Organizations must verify their current version against the affected range and prioritize the application of vendor patches immediately upon their release to prevent unauthorized system compromise.
More Oracle CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
- Oracle Advisory Vendor advisory