ZeroHour

CVE-2026-83272

large

Authenticated Takeover of Oracle Text Component in Oracle Database Server

CVSS 3.1
8.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83272 is a difficult-to-exploit vulnerability in the Oracle Text component of Oracle Database Server, rated High with a CVSS 3.1 base score of 8.5. A low-privileged attacker who already holds the Create Index privilege and has network access to the database via Oracle Net can leverage the flaw to fully compromise Oracle Text, with high impact on confidentiality, integrity, and availability. Because the vulnerability has a scope change (S:C), successful attacks may also significantly impact additional products beyond Oracle Text itself. Affected deployments are Oracle Database Server releases 19.3-19.32, 21.3-21.23, and 23.4.0-23.26.3, but exploitation requires valid credentials with Create Index rights, limiting the attacker pool to authenticated insiders or accounts whose credentials are already compromised. There is no known public proof of concept, the CVE is not on the CISA Known Exploited Vulnerabilities list, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83272 and move databases off the affected 19.3-19.32, 21.3-21.23, and 23.4.0-23.26.3 ranges. Restrict Oracle Net listener access to trusted networks and VPNs rather than exposing TCP/1521 to the internet, and audit which low-privilege accounts hold the Create Index privilege, revoking it where unnecessary. Monitor database audit logs for unexpected privilege escalation or activity originating from Oracle Text index operations.

Affected
Oracle Database Server (Oracle Text component)19.3 - 19.32
Oracle Database Server (Oracle Text component)21.3 - 21.23
Oracle Database Server (Oracle Text component)23.4.0 - 23.26.3
Estimated exposure
largetens of thousands of internet-exposed Oracle Net listeners (≈30k-40k by public scan counts) out of an enterprise install base likely in the hundreds of… — Internet-wide scans (Shodan/Censys) typically show roughly 30,000-40,000 Oracle TNS listeners reachable on TCP/1521, while the practical at-risk subset is smaller because exploitation requires authenticated access with the Create Index…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Difficult to exploit vulnerability allows low privileged attacker having Create Index privilege with network access via Oracle Net to compromise Oracle Text. While the vulnerability is in Oracle Text, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Text. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.