Executive brief
A vulnerability exists in the XML Database component of Oracle Database Server, which is used for managing and storing XML data within the database environment. An attacker could potentially gain unauthorized access to sensitive business data or all information stored within the XML Database. Exploiting this flaw is considered difficult as it requires a legitimate user to interact with a malicious link or site while the attacker targets the system over the network.
Technical details
This vulnerability is classified as an information disclosure (CWE-200) within the XML Database component of Oracle Database Server. The flaw allows an unauthenticated remote attacker to gain unauthorized access to data via HTTPS. The attack vector is network-based, but the vulnerability has high attack complexity (AC:H) and requires user interaction (UI:R) from a third party to succeed. If successfully exploited, the attacker can achieve a high confidentiality impact, gaining access to all data accessible to the XML Database component. Oracle has addressed this in the April 2026 Critical Patch Update.
Affected products
- Oracle Database Server XML Database 23.4.0-23.26.1
Timeline
- 2026-04-21: disclosed
- 2026-04-21: advisory: Oracle released the April 2026 Critical Patch Update.
- 2026-04-21: patched