Executive brief
Oracle Database Server's RDBMS component contains a vulnerability that allows a low-privilege database user with specific execution rights to gain complete control over the database through a network connection. An attacker exploiting this flaw can compromise the confidentiality, integrity, and availability of all data stored in the database, potentially enabling data theft, modification, or destruction.
Technical details
This is a privilege escalation vulnerability in the RDBMS component of Oracle Database Server affecting versions 19.3–19.32, 21.3–21.23, and 23.4.0–23.26.3. The vulnerability is easily exploitable and requires the attacker to have low-privilege database access with Execute permission on the DBMS_REDEFINITION package, plus network access via Oracle Net protocol. No additional user interaction is required. Successful exploitation allows an attacker to achieve complete database takeover, compromising all three security properties (confidentiality, integrity, and availability). A patch has not yet been confirmed as available given the future publication date.
Affected products
- Oracle Database Server 19.3–19.32, 21.3–21.23, 23.4.0–23.26.3
Timeline
- 2026-09-15: disclosed