Junglewise Threat Intelligence

CVE-2026-83272: Oracle Database Server Oracle Text privilege escalation

CVE-2026-83272 · Severity: high · CVSS 8.5 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Database Server includes a search and indexing component called Oracle Text that processes full-text queries and indexes. A flaw in this component allows an attacker with limited database privileges to exploit a network-accessible vulnerability to gain complete control of the Oracle Text system and potentially other database components. This could lead to unauthorized access to sensitive data, corruption of indexed content, and service disruption.

Technical details

The vulnerability exists in the Oracle Text component of Oracle Database Server and is classified as difficult to exploit. It requires the attacker to have Create Index privilege and network access via Oracle Net. The attack is a scope-change vulnerability, meaning successful exploitation of Oracle Text can impact additional database products and components beyond Oracle Text itself. The vulnerability allows attackers to achieve complete takeover of Oracle Text, with impacts on confidentiality, integrity, and availability of the system.

Affected products

  • Oracle Database Server 19.3-19.32, 21.3-21.23, 23.4.0-23.26.3

Timeline

  • 2026-09-15: disclosed

References