CVE-2026-83271
largePrivilege Escalation to Full Takeover in Oracle Database Server RDBMS (DBMS_REDEFINITION)
Oracle Database Server's RDBMS core contains an easily exploitable flaw (CVSS 3.1: 8.8, AV:N/AC:L/PR:L) that lets a low-privileged database user who holds the EXECUTE privilege on the DBMS_REDEFINITION package escalate to complete control of the database. The attacker only needs network reachability to the database listener via Oracle Net and valid low-privileged credentials, then triggers the flaw through the DBMS_REDEFINITION package. A successful attack results in full takeover of the RDBMS with high impact on confidentiality, integrity, and availability — effectively granting the attacker database-administrator-equivalent access to all data. All currently supported release-update lines are affected: 19.3–19.32, 21.3–21.23, and 23.4.0–23.26.3. There is no known public proof of concept, the CVE is not on the CISA KEV list, and no in-the-wild exploitation has been reported, though internal-trusted or compromised accounts are realistic attack paths.
What to do: Apply the Oracle Critical Patch Update that remediates this CVE to all Database Server instances on 19c, 21c, and 23ai within the affected release-update ranges, prioritizing any listener reachable from untrusted networks. Audit who holds EXECUTE on DBMS_REDEFINITION and revoke it from accounts that do not need it, since that privilege is the prerequisite for exploitation. Restrict TNS listener access with firewall rules/IP allowlisting, enforce least-privilege schema accounts, and review database audit logs for unexpected DBMS_REDEFINITION activity.
| Oracle Database Server (RDBMS) | 19.3-19.32 |
| Oracle Database Server (RDBMS) | 21.3-21.23 |
| Oracle Database Server (RDBMS) | 23.4.0-23.26.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows low privileged attacker having Execute on DBMS_REDEFINITION privilege with network access via Oracle Net to compromise RDBMS. Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.