Vulnerability in Oracle Text of Oracle Database Server
CVE-2026-83272

8.5HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-83272?

A vulnerability exists in the Oracle Text component of Oracle Database Server that can be exploited by a low privileged attacker possessing the Create Index privilege with network access through Oracle Net. Exploiting this vulnerability may allow an adversary to compromise Oracle Text, potentially affecting other associated products as well. Successful exploitation can lead to significant security risks, including unauthorized access to sensitive data and overall system takeover.

Affected Version(s)

Oracle Database Server 19.3 <= 19.32

Oracle Database Server 21.3 <= 21.23

Oracle Database Server 23.4.0 <= 23.26.3

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.