Junglewise Threat Intelligence

CVE-2026-83351: Oracle Database Server RDBMS remote code execution

CVE-2026-83351 · Severity: high · CVSS 8.1 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Database Server is a widely-used relational database management system that stores and processes critical business data for enterprises. This vulnerability allows an unauthenticated attacker to remotely compromise the database over a network connection without authentication, potentially leading to complete takeover of the database, unauthorized access to sensitive data, and service disruption.

Technical details

This is a difficult-to-exploit unauthenticated remote code execution vulnerability in the RDBMS component of Oracle Database Server, accessible via the Oracle Net protocol. The vulnerability requires network access but no prior authentication or user interaction, though exploitation has a high attack complexity. Successful exploitation can result in complete compromise of the RDBMS, affecting confidentiality, integrity, and availability of all data managed by the database. Affected versions range from 23.4.0 through 23.26.3; patched versions should be available through Oracle's security update channels.

Affected products

  • Oracle Database Server 23.4.0-23.26.3

Timeline

  • 2026-09-15: disclosed

References