CVE-2026-83088
moderateAuthenticated Denial of Service in Oracle Database Server 23ai (RDBMS)
CVE-2026-83088 is a denial-of-service vulnerability in the RDBMS core of Oracle Database Server, affecting the 23ai release family (versions 23.4.0 through 23.26.3). A low-privileged database user with only the Authenticated User privilege and network access to the database via Oracle Net can easily trigger a hang or frequently repeatable crash, causing a complete denial of service of the RDBMS. Because the CVSS vector includes a scope change (S:C), successful attacks can also significantly impact additional products that depend on the database, such as applications sharing the host or service chain. The flaw requires valid credentials, so the primary risk is from malicious insiders, compromised application accounts, or multi-tenant environments where untrusted users hold logins. There is no known public proof of concept, the issue is not on the CISA KEV list, and no in-the-wild exploitation has been reported.
What to do: Apply Oracle's latest Critical Patch Update as soon as it is available, since Oracle patches RDBMS flaws only through CPU releases. Restrict network access to the TNS listener (port 1521) so only application servers and DBA subnets can reach it, and use IP allowlisting or a listener whitelist of valid nodes. Review authenticated user accounts, enforce least-privilege grants, and consider database resource profiles/limits and monitoring for sessions that exhaust resources to blunt crash/hang attempts from low-privileged logins.
| Oracle Database Server (RDBMS) | 23.4.0 - 23.26.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of RDBMS. CVSS 3.1 Base Score 7.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.