Executive brief
Oracle Database Server contains a vulnerability in its RDBMS component that allows a low-privileged database user with DB Link creation rights to take complete control of the database through network access. A successful exploit grants an attacker full administrative access, potentially exposing all sensitive data stored in the database and disrupting business operations that depend on it.
Technical details
This is a privilege escalation vulnerability in the RDBMS component of Oracle Database Server affecting versions 19.3-19.32, 21.3-21.23, and 23.4.0-23.26.3. The vulnerability is easily exploitable and requires the attacker to have low-level database privileges (Create DB Link permission) and network access via Oracle Net protocol. Successful exploitation allows an attacker to escalate privileges and completely compromise the database system, resulting in unauthorized access to all data, ability to modify or delete information, and denial of service. The CVSS 3.1 score of 8.8 reflects critical impacts across confidentiality, integrity, and availability.
Affected products
- Oracle Database Server 19.3-19.32, 21.3-21.23, 23.4.0-23.26.3
Timeline
- 2026-09-15: disclosed