ZeroHour

CVE-2026-83348

large

Privilege Escalation to Full Database Takeover in Oracle Database Server RDBMS

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

The core RDBMS component of Oracle Database Server contains an easily exploitable privilege escalation flaw (CVSS 3.1: 8.8) affecting supported releases 19.3-19.32, 21.3-21.23, and 23.4.0-23.26.3. It is triggered remotely over Oracle Net by a low-privileged database user who holds the CREATE DATABASE LINK privilege, abusing database-link functionality to execute code with elevated privileges. Successful exploitation results in a complete takeover of the RDBMS, with high impact on confidentiality, integrity, and availability. Any organization running the affected supported versions is exposed, whether the listener is internet-facing or only reachable by insiders and compromised credentials on the internal network. No public proof-of-concept exists, the flaw is not on the CISA Known Exploited Vulnerabilities list, and no in-the-wild exploitation is known.

What to do: Apply the Oracle Critical Patch Update that remediates this flaw; based on the stated affected ranges, the fix first appears in the releases just beyond them (19.33+, 21.24+, 23.27+ or later). Until patched, restrict Oracle Net listener ports (TCP 1521/2484) at the firewall so only application servers and DBA hosts can reach them. Audit which low-privilege accounts hold the CREATE DATABASE LINK privilege, revoke it where unneeded, and monitor for unexpected database link creation as a sign of exploitation attempts.

Affected
Oracle Database Server (RDBMS component)19.3-19.32
Oracle Database Server (RDBMS component)21.3-21.23
Oracle Database Server (RDBMS component)23.4.0-23.26.3
Estimated exposure
largeTens of thousands of internet-exposed systems (≈30k-40k publicly reachable Oracle Net/TNS listeners), plus a much larger population of internal enterprise… — Estimated from public internet scan data showing Oracle TNS listeners (TCP 1521) exposed on tens of thousands of hosts, combined with Oracle Database's large enterprise install base; the CREATE DATABASE LINK privilege requirement narrows…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows low privileged attacker having Create DB Link privilege with network access via Oracle Net to compromise RDBMS. Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.