CVE-2026-83272
largeAuthenticated Takeover of Oracle Text Component in Oracle Database Server
CVE-2026-83272 is a difficult-to-exploit vulnerability in the Oracle Text component of Oracle Database Server, rated High with a CVSS 3.1 base score of 8.5. A low-privileged attacker who already holds the Create Index privilege and has network access to the database via Oracle Net can leverage the flaw to fully compromise Oracle Text, with high impact on confidentiality, integrity, and availability. Because the vulnerability has a scope change (S:C), successful attacks may also significantly impact additional products beyond Oracle Text itself. Affected deployments are Oracle Database Server releases 19.3-19.32, 21.3-21.23, and 23.4.0-23.26.3, but exploitation requires valid credentials with Create Index rights, limiting the attacker pool to authenticated insiders or accounts whose credentials are already compromised. There is no known public proof of concept, the CVE is not on the CISA Known Exploited Vulnerabilities list, and no in-the-wild exploitation has been reported.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83272 and move databases off the affected 19.3-19.32, 21.3-21.23, and 23.4.0-23.26.3 ranges. Restrict Oracle Net listener access to trusted networks and VPNs rather than exposing TCP/1521 to the internet, and audit which low-privilege accounts hold the Create Index privilege, revoking it where unnecessary. Monitor database audit logs for unexpected privilege escalation or activity originating from Oracle Text index operations.
| Oracle Database Server (Oracle Text component) | 19.3 - 19.32 |
| Oracle Database Server (Oracle Text component) | 21.3 - 21.23 |
| Oracle Database Server (Oracle Text component) | 23.4.0 - 23.26.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Difficult to exploit vulnerability allows low privileged attacker having Create Index privilege with network access via Oracle Net to compromise Oracle Text. While the vulnerability is in Oracle Text, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Text. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.