Vulnerability in Oracle XML Developers Kit of Oracle Database Server
CVE-2026-83156

7.5HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-83156?

A vulnerability exists in the Oracle XML Developers Kit component of the Oracle Database Server, affecting specific versions from 19.3 to 23.26.3. This weakness allows a low privileged attacker, equipped with XDKC privileges and network access via Oracle Net, to compromise the Oracle XML Developers Kit. Successful exploitation could enable the attacker to take control of the component, posing significant risks to the confidentiality, integrity, and availability of the Oracle Database environment.

Affected Version(s)

Oracle Database Server 19.3 <= 19.32

Oracle Database Server 21.3 <= 21.23

Oracle Database Server 23.4.0 <= 23.26.3

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.