Junglewise Threat Intelligence

CVE-2026-83088: Oracle Database Server RDBMS denial of service

CVE-2026-83088 · Severity: high · CVSS 7.7 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Database Server, a widely used relational database platform, contains a vulnerability in its RDBMS component that allows authenticated users to cause service outages. An attacker with low-level database access can trigger the vulnerability over the network to crash or hang the database, resulting in complete loss of availability for applications and users who depend on the database.

Technical details

The vulnerability exists in the RDBMS component of Oracle Database Server versions 23.4.0 through 23.26.3 and is exploitable by an attacker with Authenticated User privilege via Oracle Net (network protocol). The vulnerability has a scope change, meaning successful exploitation can impact additional Oracle products beyond the RDBMS component itself. An attacker can trigger a denial of service condition manifesting as a hang or frequently repeatable crash of the database. The vulnerability is easily exploitable and requires no user interaction; remediation should follow Oracle's published patch guidance.

Affected products

  • Oracle Database Server 23.4.0 to 23.26.3

Timeline

  • 2026-09-15: disclosed

References