Junglewise Threat Intelligence

CVE-2026-83156: Oracle Database Server XML Developers Kit remote code execution

CVE-2026-83156 · Severity: high · CVSS 7.5 · Published 2026-09-15

Vendors: Oracle.

Executive brief

The Oracle XML Developers Kit component of Oracle Database Server is vulnerable to remote code execution. A low-privileged attacker with network access can compromise the database system, potentially leading to complete takeover of the XML processing component and unauthorized access to sensitive data or disruption of database operations.

Technical details

This is a network-accessible remote code execution vulnerability in the Oracle XML Developers Kit component requiring the attacker to possess XDKC database privilege and low user privileges. The vulnerability is accessed via Oracle Net protocol with difficult exploitation constraints (high complexity factor despite low privilege requirement). A successful exploit grants complete compromise of the XML Developers Kit component, affecting data confidentiality, integrity, and system availability. Patches are presumed available as part of Oracle's standard security release cycle.

Affected products

  • Oracle Database Server 19.3-19.32, 21.3-21.23, 23.4.0-23.26.3

Timeline

  • 2026-09-15: disclosed

References