Junglewise Threat Intelligence

CVE-2026-83160: Oracle Database Server RDBMS privilege escalation

CVE-2026-83160 · Severity: high · CVSS 8.8 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Database Server is a core relational database engine used across enterprises to store and manage critical business data. A vulnerability in the RDBMS component allows attackers with low-privilege database access to completely compromise the database, potentially gaining unauthorized access to sensitive data, modifying records, or disrupting operations. The vulnerability is easily exploitable and requires only basic table creation permissions.

Technical details

The vulnerability exists in the RDBMS component of Oracle Database Server and affects versions 23.4.0 through 23.26.3. It requires a low-privileged attacker with Create Table privilege to exploit via network access (Oracle Net protocol). The vulnerability allows for complete compromise of the RDBMS with impacts to confidentiality, integrity, and availability. No technical details on the root cause or vulnerable code path are currently available from public sources. Patches should be available through Oracle's Critical Patch Update process.

Affected products

  • Oracle Database Server 23.4.0-23.26.3

Timeline

  • 2026-09-15: disclosed

References