ZeroHour

CVE-2026-83271

large

Privilege Escalation to Full Takeover in Oracle Database Server RDBMS (DBMS_REDEFINITION)

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

Oracle Database Server's RDBMS core contains an easily exploitable flaw (CVSS 3.1: 8.8, AV:N/AC:L/PR:L) that lets a low-privileged database user who holds the EXECUTE privilege on the DBMS_REDEFINITION package escalate to complete control of the database. The attacker only needs network reachability to the database listener via Oracle Net and valid low-privileged credentials, then triggers the flaw through the DBMS_REDEFINITION package. A successful attack results in full takeover of the RDBMS with high impact on confidentiality, integrity, and availability — effectively granting the attacker database-administrator-equivalent access to all data. All currently supported release-update lines are affected: 19.3–19.32, 21.3–21.23, and 23.4.0–23.26.3. There is no known public proof of concept, the CVE is not on the CISA KEV list, and no in-the-wild exploitation has been reported, though internal-trusted or compromised accounts are realistic attack paths.

What to do: Apply the Oracle Critical Patch Update that remediates this CVE to all Database Server instances on 19c, 21c, and 23ai within the affected release-update ranges, prioritizing any listener reachable from untrusted networks. Audit who holds EXECUTE on DBMS_REDEFINITION and revoke it from accounts that do not need it, since that privilege is the prerequisite for exploitation. Restrict TNS listener access with firewall rules/IP allowlisting, enforce least-privilege schema accounts, and review database audit logs for unexpected DBMS_REDEFINITION activity.

Affected
Oracle Database Server (RDBMS)19.3-19.32
Oracle Database Server (RDBMS)21.3-21.23
Oracle Database Server (RDBMS)23.4.0-23.26.3
Estimated exposure
largeOrder of magnitude: tens of thousands of internet-exposed Oracle TNS listeners (≈10k-100k), with total affected installations plausibly in the hundreds of… — Oracle Database runs on-premises at a large share of enterprises worldwide, and public internet scans (Shodan/Censys) have historically shown roughly tens of thousands of internet-reachable Oracle TNS listeners; exploitability is narrower…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows low privileged attacker having Execute on DBMS_REDEFINITION privilege with network access via Oracle Net to compromise RDBMS. Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.