Description
Vulnerability in the Oracle XML Developers Kit component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Difficult to exploit vulnerability allows low privileged attacker having XDKC privilege with network access via Oracle Net to compromise Oracle XML Developers Kit. Successful attacks of this vulnerability can result in takeover of Oracle XML Developers Kit. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation (Takeover
Action: Patch Now
AI Analysis

Impact

The vulnerability lies in Oracle's XML Developers Kit component of Oracle Database Server. Attackers who already possess low‑privileged XDKC rights and can reach the system over Oracle Net can exploit this flaw, gaining full control of the XML Developers Kit. Successful exploitation compromises the confidentiality, integrity, and availability of the system because the attacker can take over the component, alter configurations, or disrupt that rely on XML processing.

Affected Systems

Oracle Corporation’s Oracle Database Server, specifically the Oracle XML Developers Kit. Versions 19.3 through 19.32, 21.3 through 21.23, and 23.4.0 through 23.26.3 are affected.

Risk and Exploitability

The CVSS v3.1 base score of 7.5 indicates a high severity, while the EPSS score (<1%) shows a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers need network access via Oracle Net andC rights to succeed, and the exploit provides full takeover of the XML Developers Kit, impacting all database services that depend on this component.

Generated by OpenCVE AI on September 17, 2026 at 02:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Database Server patch or upgrade to a product version that is not affected by this vulnerability.
  • Restrict Oracle Net access to the database server to trusted networks and limit XDKC privileges to only those accounts that truly require required for your environment, uninstall or disable the component to reduce the attack surface.
  • Enable audit logging for XML Developers Kit operations and regularly review logs for abnormal activity that could indicate exploitation.

Generated by OpenCVE AI on September 17, 2026 at 02:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Title Remote Takeover of Oracle XML Developers Kit via Low-Privilege Network Access
Weaknesses CWE-269
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle XML Developers Kit component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Difficult to exploit vulnerability allows low privileged attacker having XDKC privilege with network access via Oracle Net to compromise Oracle XML Developers Kit. Successful attacks of this vulnerability can result in takeover of Oracle XML Developers Kit. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle database - E Xml Developers Kit
CPEs cpe:2.3:a:oracle:database_-_e_xml_developers_kit:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle database - E Xml Developers Kit
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Database - E Xml Developers Kit
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T20:03:39.942Z

Reserved: 2026-08-31T15:40:57.343Z

Link: CVE-2026-83156

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:26.417

Modified: 2026-09-16T19:36:43.087

Link: CVE-2026-83156

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T02:45:18Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control