Description
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of RDBMS. CVSS 3.1 Base Score 7.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H).
Published: 2026-09-15
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

Oracle Database Server contains a vulnerability in its RDBMS component that permits an authenticated low‑privilege user with network access via Oracle Net to trigger a termination of the RDBMS. Because the flaw directly impacts availability, an attacker can repeatedly cause the database to hang or crash, leading to a complete denial of service. The vulnerability is an authentication privilege abuse (CWE‑284) that requires only modest effort to exploit and is described as easily exploitable.

Affected Systems

The issue affects Oracle Database Server releases 23.4.0 through 23.26.3, as identified by the vendor. All installations of those versions that are reachable over Oracle Net and allow authentication with user privileges are at risk. The advisory does not specify platform or operating‑system requirements beyond the database versions.

Risk and Exploitability

Based on the CVSS 3.1 base score of 7.7 and the vector (AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H), the flaw presents a moderate to high impact on availability with a low attacker effort and a local privileged user network requirement. The EPSS score is below 1 %, indicating a very low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw can affect other products when in scope, the attack surface expands beyond the RDBMS alone. An attacker would need valid authentication credentials and network access; once authenticated, they can repeatedly issue the failing command until the database crashes.

Generated by OpenCVE AI on September 18, 2026 at 21:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Oracle Database Server patches or updates that address CVE-2026-83088 as published in the Oracle Security Alert.
  • Restrict Oracle Net traffic (e.g., firewall or VLAN) to trusted hosts only and reduce the number of authenticated users with database access.
  • Review and limit privileges for database accounts, ensuring that only those requiring access are granted at minimum necessary level.

Generated by OpenCVE AI on September 18, 2026 at 21:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Authenticated Low-Privilege Remote Denial of Service in Oracle Database Server RDBMS

Thu, 17 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Title Authenticated Low-Privilege Remote Denial of Service in Oracle Database Server RDBMS

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Oracle Corporation
Oracle Corporation oracle Database Server
Weaknesses CWE-284
Vendors & Products Oracle Corporation
Oracle Corporation oracle Database Server

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of RDBMS. CVSS 3.1 Base Score 7.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H).
First Time appeared Oracle
Oracle database - Rdbms
CPEs cpe:2.3:a:oracle:database_-_rdbms:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle database - Rdbms
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H'}


Subscriptions

Oracle Database - Rdbms
Oracle Corporation Oracle Database Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T17:58:24.702Z

Reserved: 2026-08-31T15:40:57.339Z

Link: CVE-2026-83088

cve-icon Vulnrichment

Updated: 2026-09-16T17:55:58.653Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:18.617

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-83088

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T21:30:14Z

Weaknesses