CVE-2026-83348

8.8

Oracle · Oracle Database Server

A vulnerability in the Oracle Database Server RDBMS component allows a low privileged attacker with Create DB Link privileges to compromise the database.

Executive summary

An authenticated attacker with low privileges can achieve a full takeover of the Oracle Database Server, creating a significant risk of data compromise and system instability.

Vulnerability

This is an easily exploitable vulnerability in the RDBMS component that allows an attacker with low-level privileges (specifically the Create DB Link privilege) to gain unauthorized control over the database via Oracle Net.

Business impact

The potential for a complete takeover of the RDBMS presents a critical threat to business operations, as it allows for the total loss of confidentiality, integrity, and availability of sensitive organizational data. With a CVSS base score of 8.8, this high-severity vulnerability poses a substantial risk of unauthorized data exfiltration, permanent data corruption, and prolonged service outages.

Remediation

Immediate Action: Review the official Oracle Security Alert (https://www.oracle.com/security-alerts/cspusep2026.html) and apply the latest security patches to the affected database instances immediately.

Proactive Monitoring: Audit all existing database links and monitor network traffic via Oracle Net for unusual connection patterns or unauthorized attempts to leverage the Create DB Link privilege.

Compensating Controls: Restrict the Create DB Link privilege to the absolute minimum set of users and implement strict network segmentation to limit access to the database listener from untrusted network segments.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the severity of this vulnerability and the potential for a full database takeover, organizations must prioritize patching their Oracle Database environments. Administrators should immediately audit user privileges to identify accounts with the Create DB Link permission and revoke access for any users who do not strictly require it for their roles while awaiting the application of vendor-supplied patches.

More Oracle CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources