ZeroHour

CVE-2026-83351

large

Unauthenticated Remote Takeover of Oracle Database Server RDBMS via Oracle Net

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83351 is a difficult-to-exploit vulnerability in the core RDBMS component of Oracle Database Server, affecting supported releases 23.4.0 through 23.26.3. An unauthenticated attacker with network reachability to the database's Oracle Net (TNS) listener — with no privileges and no user interaction required — can exploit the flaw and take over the RDBMS, gaining full impact to confidentiality, integrity, and availability (CVSS 3.1 base score 8.1). The high attack-complexity rating (AC:H) means reliable exploitation likely requires significant skill or favorable conditions, somewhat lowering practical risk. Any organization running an affected 23.x Oracle Database Server release that is reachable over the network is in scope, though database servers exposed directly to the internet face the greatest risk. There is no public proof of concept and the CVE is not on the CISA KEV list, so no exploitation is currently known.

What to do: Apply the Oracle Critical Patch Update containing the fix for CVE-2026-83351, moving any 23.4.0-23.26.3 database to the patched release. Restrict Oracle Net/TNS listener (TCP 1521 and any configured listener ports) so it is reachable only from trusted application and admin hosts — it should never be directly exposed to the internet. Verify listener configuration, enable TNS authentication/encryption controls, and review database and listener logs for unexpected connection attempts while patching is scheduled.

Affected
Oracle Database Server (RDBMS component)23.4.0 - 23.26.3
Estimated exposure
large≈ tens of thousands of internet-exposed Oracle Net/TNS listeners (port 1521) per public scan data, with only a subset running affected 23.x releases — Public internet scans (e.g., Shodan/Censys) have historically shown on the order of tens of thousands of devices with Oracle TNS listener port 1521 open, and Oracle Database is deployed at hundreds of thousands of organizations worldwide,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise RDBMS. Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.