Description
Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise XML Database. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all XML Database accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N).
Published: 2026-04-21
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data access via HTTPS
Action: Assess Impact
AI Analysis

Impact

The vulnerability resides in the XML Database component of Oracle Database Server. An unauthenticated attacker who can reach the HTTPS interface can potentially retrieve any accessible XML data. The flaw is described as difficult to exploit and requires the involvement of a distinct human actor; however, if successful, it allows unauthorized data access or complete takeover of the XML Database. The weakness is classified as CWE-200 (Information Exposure). The weakness primarily impacts confidentiality, as indicated by the high confidentiality impact in the CVSS vector.

Affected Systems

Affected products include Oracle Corporation's Oracle Database Server, specifically the XML Database component. The affected versions are 23.4.0 through 23.26.1. No other versions or products are mentioned. The failure to restrict access pertains only to the XML Database service exposed via HTTPS.

Risk and Exploitability

The CVSS base score of 5.3 places the issue in the medium severity range, with a high confidentiality impact but no integrity or availability impact. The EPSS score is < 1%, indicating a very low but non‑zero likelihood of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote HTTPS access, and the vulnerability mandates human interaction beyond the attacker, which could lower practical exploitation probability. Nevertheless, the flaw permits unauthorized data access if an attacker overcomes the interaction hurdle.

Generated by OpenCVE AI on April 28, 2026 at 21:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch(s) released in Oracle’s April 2026 CPU advisory for the affected XML Database versions
  • If patching cannot be performed immediately, block external HTTPS access to the XML Database service through firewall rules or network segmentation
  • Restrict XML Database permissions to authorized accounts only and audit access logs for anomalous activity

Generated by OpenCVE AI on April 28, 2026 at 21:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Apr 2026 21:45:00 +0000

Type Values Removed Values Added
Title Oracle XML Database Vulnerability Allows Unauthorized Data Access via HTTPS

Tue, 28 Apr 2026 09:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated XML Database Access via HTTPS in Oracle Database Server
Weaknesses CWE-284

Wed, 22 Apr 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Wed, 22 Apr 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Oracle database Server
Vendors & Products Oracle database Server

Wed, 22 Apr 2026 03:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated XML Database Access via HTTPS in Oracle Database Server
Weaknesses CWE-284

Wed, 22 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise XML Database. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all XML Database accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle database - Xml Database
CPEs cpe:2.3:a:oracle:database_-_xml_database:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle database - Xml Database
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Database - Xml Database Database Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-04-22T14:04:56.332Z

Reserved: 2026-01-05T18:07:34.724Z

Link: CVE-2026-21999

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-04-21T21:16:25.060

Modified: 2026-04-22T21:24:26.997

Link: CVE-2026-21999

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T21:30:26Z

Weaknesses