CVE-2026-83351
largeUnauthenticated Remote Takeover of Oracle Database Server RDBMS via Oracle Net
CVE-2026-83351 is a difficult-to-exploit vulnerability in the core RDBMS component of Oracle Database Server, affecting supported releases 23.4.0 through 23.26.3. An unauthenticated attacker with network reachability to the database's Oracle Net (TNS) listener — with no privileges and no user interaction required — can exploit the flaw and take over the RDBMS, gaining full impact to confidentiality, integrity, and availability (CVSS 3.1 base score 8.1). The high attack-complexity rating (AC:H) means reliable exploitation likely requires significant skill or favorable conditions, somewhat lowering practical risk. Any organization running an affected 23.x Oracle Database Server release that is reachable over the network is in scope, though database servers exposed directly to the internet face the greatest risk. There is no public proof of concept and the CVE is not on the CISA KEV list, so no exploitation is currently known.
What to do: Apply the Oracle Critical Patch Update containing the fix for CVE-2026-83351, moving any 23.4.0-23.26.3 database to the patched release. Restrict Oracle Net/TNS listener (TCP 1521 and any configured listener ports) so it is reachable only from trusted application and admin hosts — it should never be directly exposed to the internet. Verify listener configuration, enable TNS authentication/encryption controls, and review database and listener logs for unexpected connection attempts while patching is scheduled.
| Oracle Database Server (RDBMS component) | 23.4.0 - 23.26.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise RDBMS. Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.