CVE-2026-83160
moderateAuthenticated Database Takeover in Oracle Database Server 23.x RDBMS
CVE-2026-83160 is a high-severity (CVSS 8.8) vulnerability in the RDBMS component of Oracle Database Server affecting supported versions 23.4.0 through 23.26.3. It is easily exploitable by a low-privileged attacker who already holds the Create Table privilege and has network access to the database via Oracle Net. Successful exploitation allows complete takeover of the RDBMS, with high impact on confidentiality, integrity, and availability of all data in the database. In practice this is an insider/compromised-account threat vector: the attacker must authenticate with a schema able to create tables (e.g., an application or developer account), so internet-exposed listeners are at greatest risk but any multi-user database is in scope. No public proof-of-concept exists, the flaw is not on CISA's KEV list, and no exploitation in the wild has been reported.
What to do: Apply Oracle's latest Critical Patch Update and upgrade affected 23.x databases past 23.26.3 to the current Release Update as soon as possible. Restrict Oracle Net listener access to trusted networks via firewalls and valid node checking — TNS ports should never face the internet — and enable TNS auditing. Audit which accounts hold the CREATE TABLE privilege, revoke it where unnecessary, and rotate credentials for low-privilege schema accounts while monitoring for unexpected privilege escalation or SYSDBA activity.
| Oracle Database Server (RDBMS component) | 23.4.0 - 23.26.3 (supported versions) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows low privileged attacker having Create Table privilege with network access via Oracle Net to compromise RDBMS. Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.