Executive brief
The Oracle XML Developers Kit component of Oracle Database Server is vulnerable to remote code execution. A low-privileged attacker with network access can compromise the database system, potentially leading to complete takeover of the XML processing component and unauthorized access to sensitive data or disruption of database operations.
Technical details
This is a network-accessible remote code execution vulnerability in the Oracle XML Developers Kit component requiring the attacker to possess XDKC database privilege and low user privileges. The vulnerability is accessed via Oracle Net protocol with difficult exploitation constraints (high complexity factor despite low privilege requirement). A successful exploit grants complete compromise of the XML Developers Kit component, affecting data confidentiality, integrity, and system availability. Patches are presumed available as part of Oracle's standard security release cycle.
Affected products
- Oracle Database Server 19.3-19.32, 21.3-21.23, 23.4.0-23.26.3
Timeline
- 2026-09-15: disclosed