Description
Vulnerability in the Oracle XML Developers Kit component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Difficult to exploit vulnerability allows low privileged attacker having XDKC privilege with network access via Oracle Net to compromise Oracle XML Developers Kit. Successful attacks of this vulnerability can result in takeover of Oracle XML Developers Kit. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation (Takeover)
Action: Patch Now
AI Analysis

Impact

The flaw in Oracle’s XML Developers Kit allows an attacker who already has low‑privileged XDKC rights and can reach the system over Oracle Net to gain full control of the component. Successful exploitation compromises the confidentiality, integrity, and availability of all database services that rely on XML processing.

Affected Systems

Oracle Database Server, specifically the XML Developers Kit component. Versions 19.3–19.32, 21.3–21.23, and 23.4.0–23.26.3 are affected.

Risk and Exploitability

The CVSS v3.1 base score of 7.5 indicates high severity, while the EPSS score of < 1 % shows a very low likelihood of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Attackers need network access via Oracle Net and possession of XDKC privileges to succeed, providing them with full takeover of the XML Developers Kit.

Generated by OpenCVE AI on September 20, 2026 at 09:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle Database Server patch that addresses this vulnerability or upgrade to a non‑affected product version.
  • Restrict Oracle Net access to the database server to trusted networks and remove or revoke XDKC privileges from accounts that do not require them.
  • Enable auditing for XML Developers Kit operations and regularly review logs for anomalous activity that may indicate exploitation.

Generated by OpenCVE AI on September 20, 2026 at 09:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle XML Developers Kit over Oracle Net

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Remote Takeover of Oracle XML Developers Kit via Low-Privilege Network Access
Weaknesses CWE-269

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Oracle database Server
Vendors & Products Oracle database Server

Thu, 17 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Title Remote Takeover of Oracle XML Developers Kit via Low-Privilege Network Access
Weaknesses CWE-269
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle XML Developers Kit component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Difficult to exploit vulnerability allows low privileged attacker having XDKC privilege with network access via Oracle Net to compromise Oracle XML Developers Kit. Successful attacks of this vulnerability can result in takeover of Oracle XML Developers Kit. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle database - E Xml Developers Kit
CPEs cpe:2.3:a:oracle:database_-_e_xml_developers_kit:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle database - E Xml Developers Kit
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Database - E Xml Developers Kit Database Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:17:27.112Z

Reserved: 2026-08-31T15:40:57.343Z

Link: CVE-2026-83156

cve-icon Vulnrichment

Updated: 2026-09-17T14:58:40.602Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:26.417

Modified: 2026-09-17T16:18:05.717

Link: CVE-2026-83156

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T09:30:18Z

Weaknesses